The federal government’s AusweisApp website was intermittently inaccessible to some users on Saturday, September 26, 2026. D-Trust, the certification authority of the Bundesdruckerei Group, had already revoked the TLS certificate for ausweisapp.bund.de on Friday. Consequently, browsers such as Firefox and—in some cases—Chrome responded with certificate warnings or blocked access. The reason cited for the revocation was “privilegeWithdrawn,” although no public explanation was initially provided. There were no indications that a private key had been compromised. According to available information, the online ID function itself did not suffer a general outage. On Saturday evening, the website finally received a new certificate and became accessible again.

Image: Shutterstock
AusweisApp certificate revoked with unusual revocation reason
A TLS certificate verifies a server’s identity to the browser and enables an encrypted connection. If the certificate authority revokes a certificate, browsers may consequently refuse to establish a connection. This is precisely what happened with ausweisapp.bund.de, although the reaction varied depending on the browser and the currency of the revocation information.
Of particular note, however, is the recorded revocation reason: “privilegeWithdrawn.” According to current CA/Browser Forum guidelines, this code indicates specific violations or changes on the part of the certificate holder. These may include incorrect information, breaches of contract, or significant changes to certificate data. By contrast, a compromised private key falls explicitly under the separate reason “keyCompromise.” Therefore, the incident does not imply a hacker attack or the loss of a key.
Operator structure had changed just weeks earlier
However, an organizational change regarding the operator stands out. In August 2026, the former Governikus GmbH & Co. KG was converted into Governikus Service GmbH. The commercial register records this change as taking effect on August 14. The AusweisApp’s current legal notice also now lists Governikus Service GmbH as the party responsible for operations on behalf of the Federal Office for Information Security (BSI).
However, it has not yet been officially confirmed whether this corporate restructuring actually triggered the certificate revocation. From a technical standpoint, a change in relevant company data could certainly be a reason for renewing a certificate. Yet, the revocation reason alone does not prove this connection. Initially, D-Trust did not publish a publicly verifiable explanation for this specific case.
Website Affected – Online ID Functionality Apparently Uninterrupted
For users, the distinction between the website and the actual application is also crucial. The software is used to read data from the national ID card, the electronic residence permit, or the eID card. It also enables encrypted data exchange with online services. Consequently, the certificate issue affecting the website did not automatically result in a failure of this identification process.
According to user reports, versions of the AusweisApp that were already installed continued to function. Disruptions primarily occurred when users attempted to access the official website or download the software from it. On the evening of September 26, ausweisapp.bund.de received a new certificate, causing the browser warnings to disappear. The actual technical impact was therefore limited. Nevertheless, in the case of a centralized government identity solution, an unexplained certificate revocation is significant, as the chain of trust directly determines the security of the access process.
Author: Blackout News
Sources: Heise (26.09.26) – Blogspan (26.09.26)
