← Internet Security Research Group cases
Bugzilla #1398427 Ca Certificate Compliance Certificate Misissuance

Let's Encrypt: CAA Misissuances

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug reports that Let's Encrypt issued certificates that allegedly violated the CA/B Forum Baseline Requirements CAA checking requirement. The reporter cited two specific certificates and argued that Certificate #1 should not have been issued because the relevant DNS name lacked a CAA record, and that Certificate #2 should not have been issued because the DNSSEC signatures were expired, so CAA lookup should have failed. Mozilla asked the CA to acknowledge the problem, provide a timeline, and submit an incident report. Let's Encrypt stated that within 24 hours of receiving the report it investigated both issues, confirmed certificate details, revoked both certificates, deployed fixes to production infrastructure, and communicated results to the reporter. For Certificate #1, Let's Encrypt said it considered the behavior technically non-compliant but chose not to change its behavior immediately, while revoking certificates if requested by subscribers and noting it would consider changes if Mozilla requested. For Certificate #2, Let's Encrypt said it deployed a production change to eliminate clock-skew allowance in its resolver. Later, Let's Encrypt reported deploying a change to bring its CAA checking algorithm into compliance and requested public permission from the Mozilla root program to revert to its earlier algorithm. Mozilla stated that the issue relating to Certificate #2 had been remediated and that, given Mozilla’s position, Certificate #1 was not misissued.

Model: gpt-5.4-nano Generated: 2026-06-13 11:59 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.86 6 comments
Chronology
  1. The reporter submitted a report alleging CAA-checking violations tied to two Let's Encrypt certificates.
  2. Let's Encrypt revoked the two certificates and deployed production fixes within 24 hours of receiving the report.
  3. Let's Encrypt deployed a change to its CAA checking algorithm to bring it into compliance.
  4. Mozilla indicated Certificate #2’s issue was remediated and that Certificate #1 was not misissued per Mozilla’s position.
Thread Activity
  1. Mm representative — Reported that Let's Encrypt issued two certificates allegedly in violation of the Baseline Requirements CAA checking requirement, providing DNS/CAA and DNSSEC reasoning and links to crt.sh.
  2. Mozilla representative — Asked Josh to update the bug with acknowledgement, a timeline, and to provide an incident report as described in the Mozilla wiki link.
  3. Kflag representative — Stated that within 24 hours of receiving the report Let's Encrypt investigated, confirmed details, revoked both certificates, deployed production fixes, and communicated results; described its rationale for not changing behavior for Certificate #1 and its clock-skew fix for Certificate #2.
  4. Kflag representative — Reported that on Sep 14 it deployed a CAA-checking algorithm change into compliance, noted subsequent reports of problems, and requested public permission from the Mozilla root program to revert to the prior algorithm (with a link to a mailing list message).
  5. Mozilla representative — Posted a link to the referenced mozilla.dev.security.policy thread message.
  6. Mozilla representative — Said that given Mozilla’s position, cert #1 is not misissued and that the issue relating to cert #2 has been remediated.
Participants
Mm representative Mozilla representative Kflag representative
Similar Local Cases
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 100% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1462735 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 99% similar
Let's Encrypt: Case-sensitive CAA tag processing
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 90% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 89% similar
Let's Encrypt: Duplicate Serial Numbers
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 85% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 85% similar
SHA-1 issuance by DocuSign root
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action