Let's Encrypt: CAA Misissuances
The bug reports that Let's Encrypt issued certificates that allegedly violated the CA/B Forum Baseline Requirements CAA checking requirement. The reporter cited two specific certificates and argued that Certificate #1 should not have been issued because the relevant DNS name lacked a CAA record, and that Certificate #2 should not have been issued because the DNSSEC signatures were expired, so CAA lookup should have failed. Mozilla asked the CA to acknowledge the problem, provide a timeline, and submit an incident report. Let's Encrypt stated that within 24 hours of receiving the report it investigated both issues, confirmed certificate details, revoked both certificates, deployed fixes to production infrastructure, and communicated results to the reporter. For Certificate #1, Let's Encrypt said it considered the behavior technically non-compliant but chose not to change its behavior immediately, while revoking certificates if requested by subscribers and noting it would consider changes if Mozilla requested. For Certificate #2, Let's Encrypt said it deployed a production change to eliminate clock-skew allowance in its resolver. Later, Let's Encrypt reported deploying a change to bring its CAA checking algorithm into compliance and requested public permission from the Mozilla root program to revert to its earlier algorithm. Mozilla stated that the issue relating to Certificate #2 had been remediated and that, given Mozilla’s position, Certificate #1 was not misissued.
- The reporter submitted a report alleging CAA-checking violations tied to two Let's Encrypt certificates.
- Let's Encrypt revoked the two certificates and deployed production fixes within 24 hours of receiving the report.
- Let's Encrypt deployed a change to its CAA checking algorithm to bring it into compliance.
- Mozilla indicated Certificate #2’s issue was remediated and that Certificate #1 was not misissued per Mozilla’s position.
- Mm representative — Reported that Let's Encrypt issued two certificates allegedly in violation of the Baseline Requirements CAA checking requirement, providing DNS/CAA and DNSSEC reasoning and links to crt.sh.
- Mozilla representative — Asked Josh to update the bug with acknowledgement, a timeline, and to provide an incident report as described in the Mozilla wiki link.
- Kflag representative — Stated that within 24 hours of receiving the report Let's Encrypt investigated, confirmed details, revoked both certificates, deployed production fixes, and communicated results; described its rationale for not changing behavior for Certificate #1 and its clock-skew fix for Certificate #2.
- Kflag representative — Reported that on Sep 14 it deployed a CAA-checking algorithm change into compliance, noted subsequent reports of problems, and requested public permission from the Mozilla root program to revert to the prior algorithm (with a link to a mailing list message).
- Mozilla representative — Posted a link to the referenced mozilla.dev.security.policy thread message.
- Mozilla representative — Said that given Mozilla’s position, cert #1 is not misissued and that the issue relating to cert #2 has been remediated.