Amazon Trust Services: CAA checking misissuances (CAA record/DNSSEC edge cases)
The bug was opened after a reporter alleged that a CA operated by DigiCert (cross-signed by Amazon and chaining to an Amazon-owned root) issued certificates in violation of the Baseline Requirements CAA checking requirement. The reporter provided six certificate examples and described DNS/CAA/DNSSEC scenarios where, according to the report, the CA should not have issued. Mozilla asked the CA operator to acknowledge the problem and provide a timeline and an incident report. ATS and DigiCert stated they received an email from the reporter, described their communications with the reporter, and said they would determine what actions were necessary after assessing whether the reports demonstrated legitimate issues. Later, ATS stated that DigiCert and ATS were making good-faith efforts to implement RFC 6844 (as amended by erratum 5065) and that the tests helped clarify ambiguous requirements; ATS said Mozilla should consider the issue resolved. The thread includes follow-up questions about whether the specific issue behind certificate 1 was fixed, and DigiCert confirmed it was fixed and that they use UDP or TCP as appropriate. The bug is marked RESOLVED with resolution FIXED.
- A CA certificate compliance issue related to CAA checking was reported with multiple certificate examples.
- ATS and DigiCert submitted revocation requests for the reported certificates.
- DigiCert confirmed the certificate 1 issue was fixed and that UDP/TCP is used appropriately.
- Mm representative — Submitted revocation requests and detailed six alleged CAA-checking violations with links to the affected certificates and DNS/CAA/DNSSEC reasoning.
- Mozilla representative — Asked for prompt bug updates acknowledging the problem, a timeline for resolving the immediate problem, and an incident report per Mozilla guidance.
- DigiCert — Reported that ATS and DigiCert received the reporter’s email, described response times and ongoing communication, and said ATS would determine necessary actions after assessing whether the reports were legitimate.
- Mozilla representative — Asked whether any of the reported issues were still considered misissuances given Mozilla’s stated expectations for CAA checking.
- Community commenter — Asked for updates.
- DigiCert — Stated that DigiCert and ATS were making good-faith efforts to implement RFC 6844 (with erratum 5065) and that Mozilla should consider the issue resolved.
- Mm representative — Clarified that certificate 1 was not related to CNAME, DNAME, or DNSSEC.
- DigiCert — Apologized for the implication and referenced prior discussion indicating certificate 1 was being fixed.
- Mozilla representative — Asked Jeremy to confirm the issue leading to certificate 1 is fixed.
- DigiCert — Confirmed the certificate 1 issue was fixed and that UDP or TCP is used as appropriate.