← Amazon Trust Services cases
Bugzilla #1398428 Ca Certificate Compliance Certificate Misissuance

Amazon Trust Services: CAA checking misissuances (CAA record/DNSSEC edge cases)

RESOLVED FIXED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened after a reporter alleged that a CA operated by DigiCert (cross-signed by Amazon and chaining to an Amazon-owned root) issued certificates in violation of the Baseline Requirements CAA checking requirement. The reporter provided six certificate examples and described DNS/CAA/DNSSEC scenarios where, according to the report, the CA should not have issued. Mozilla asked the CA operator to acknowledge the problem and provide a timeline and an incident report. ATS and DigiCert stated they received an email from the reporter, described their communications with the reporter, and said they would determine what actions were necessary after assessing whether the reports demonstrated legitimate issues. Later, ATS stated that DigiCert and ATS were making good-faith efforts to implement RFC 6844 (as amended by erratum 5065) and that the tests helped clarify ambiguous requirements; ATS said Mozilla should consider the issue resolved. The thread includes follow-up questions about whether the specific issue behind certificate 1 was fixed, and DigiCert confirmed it was fixed and that they use UDP or TCP as appropriate. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:25 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.86 10 comments
Chronology
  1. A CA certificate compliance issue related to CAA checking was reported with multiple certificate examples.
  2. ATS and DigiCert submitted revocation requests for the reported certificates.
  3. DigiCert confirmed the certificate 1 issue was fixed and that UDP/TCP is used appropriately.
Thread Activity
  1. Mm representative — Submitted revocation requests and detailed six alleged CAA-checking violations with links to the affected certificates and DNS/CAA/DNSSEC reasoning.
  2. Mozilla representative — Asked for prompt bug updates acknowledging the problem, a timeline for resolving the immediate problem, and an incident report per Mozilla guidance.
  3. DigiCert — Reported that ATS and DigiCert received the reporter’s email, described response times and ongoing communication, and said ATS would determine necessary actions after assessing whether the reports were legitimate.
  4. Mozilla representative — Asked whether any of the reported issues were still considered misissuances given Mozilla’s stated expectations for CAA checking.
  5. Community commenter — Asked for updates.
  6. DigiCert — Stated that DigiCert and ATS were making good-faith efforts to implement RFC 6844 (with erratum 5065) and that Mozilla should consider the issue resolved.
  7. Mm representative — Clarified that certificate 1 was not related to CNAME, DNAME, or DNSSEC.
  8. DigiCert — Apologized for the implication and referenced prior discussion indicating certificate 1 was being fixed.
  9. Mozilla representative — Asked Jeremy to confirm the issue leading to certificate 1 is fixed.
  10. DigiCert — Confirmed the certificate 1 issue was fixed and that UDP or TCP is used as appropriate.
Participants
Mm representative DigiCert Mozilla representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1521623 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-01-21 · Closed 2024-05-09 · 91% similar
Amazon Trust Services: Failure to comply with RFC 5280
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 83% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 79% similar
DigiCert: Invalid localityName
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 78% similar
GlobalSign: CRL contains invalid signature algorithm
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 77% similar
Let's Encrypt: CAA Misissuances
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 77% similar
QuoVadis: EV serialNumber with "none"
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 77% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 77% similar
KIR S.A.: Invalid organizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action