Heise reports that browsers have stopped trusting the TLS certificate for Germany's AusweisApp after certificate authority D-Trust revoked it on September 25. The domain involved is ausweisapp.bund.de, and the revocation was logged with the reason 'Privilege Withdrawn'.
That wording does not necessarily mean the private key was compromised. Instead, it often signals a misuse of the certificate, a change in eligibility, or an issuance that should not have happened under the CA/Browser Forum baseline requirements. In practice, it tells users that the certificate should no longer be relied upon even if the technical chain once looked valid.
For anyone depending on AusweisApp, the immediate issue is not theoretical. If browsers reject the certificate, web-based parts of the identity workflow can fail or prompt scary warnings, which is a bad look for a government identity app. Heise says two other certificates for the same domain still appear valid for now, but the revoked one is the immediate trust problem.
The story matters beyond Germany because it shows how fragile public digital identity infrastructure can be when it rests on a single certificate trust chain. One unexpected revocation can make a sensitive government tool look broken overnight, even if the broader system is still technically intact.



