← Internet Security Research Group cases
Bugzilla #1398427 Certificate Misissuance

Let's Encrypt: CAA Misissuances

RESOLVED Internet Security Research Group
AI Summary

This case addresses misissuances by Let's Encrypt related to CAA checking requirements. Two certificates were issued in violation of the Baseline Requirements, prompting an investigation and subsequent revocation of the certificates. Let's Encrypt acknowledged the compliance issues and implemented changes to their CAA checking algorithm to align with the requirements. The matter was resolved with a commitment to ongoing compliance.

Model: gpt-4o-mini Generated: 2026-06-13 11:59 UTC Confidence: 0.95
Chronology
  1. Initial report of CAA misissuances
  2. Certificates revoked and fixes deployed
  3. CAA checking algorithm updated for compliance
  4. Mozilla confirmed no misissuance for cert #1
Participants
Josh Aas Andrew Ayer Kathleen Wilson Gervase Markham
Similar Local Cases
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 66% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1398428 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 65% similar
Amazon Trust Services: CAA Misissuances
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 63% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 57% similar
SHA-1 issuance by Visa root
#1405815 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 56% similar
Camerfirma: Certs issued with same issuer and serial number
#1386891 RESOLVED Certificate Misissuance Opened 2017-08-02 · Closed 2023-02-22 · 56% similar
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
#1313873 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DocuSign root
#1313872 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DigiCert roots

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action