D-Trust, the Bundesdruckerei-operated certificate authority, revoked the X.509/TLS certificate for ausweisapp.bund.de on September 25. Browsers will no longer trust the revoked certificate, potentially presenting certificate-security warnings to users accessing the German electronic-ID application’s domain; two other TLS certificates for the domain reportedly remain valid.
The certificate revocation list cites “Privilege Withdrawn” as the reason. That status does not alone indicate private-key compromise: it can reflect unauthorized or improper certificate use, changes to certificate-holder information, or a certificate issued in error. The precise cause had not been publicly disclosed, and Bundesdruckerei had not responded to media inquiries.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
The issuing certificate authority revoked the X.509/TLS certificate for ausweisapp.bund.de (serial number 7D0D9F5C1471C81F53BFFF2626EF925918217A35) at 13:55:06 GMT. The revocation list recorded the reason as “Privilege Withdrawn”; the specific cause was not publicly known.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.