← DigiCert cases
Bugzilla #1409735 Ca Certificate Compliance

DigiCert/RapidSSL: CAA mis-issuance due to CAA lookup timeout on DNSSEC-signed zone

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case describes a certificate mis-issuance involving RapidSSL (Symantec legacy systems) where a certificate was issued despite the requester’s claim that CAA permission should not have been granted. The requester reported that the test domain was DNSSEC-signed and had a CAA record, but the server was configured not to reply to CAA queries, causing CAA lookups to time out. The bug thread states that the lookup failure must not be treated as permission to issue when DNSSEC validation is present, referencing CAB Ballot 187. DigiCert’s incident report states that the CA confirmed the issue, ordered revocation, and started analysis, then revoked the affected certificate(s) on 2017-10-19/2017-10-20. The CA determined the cause as incorrect handling of CAA response when CAA fetch timed out at the base domain and software rules improperly treated an empty set from the TLD or public suffix as permission to issue. DigiCert states it wrote and applied a patch to correct DNSSEC record checking (with a later identifier issue impacting one certificate), installed a change to stop treating a successful empty set fetch at the TLD/PSL as permission to issue, and applied further investigation after the patch. The thread concludes with a comment from Mozilla marking the bug resolved after actions were completed and questions answered.

Model: gpt-5.4-nano Generated: 2026-06-13 11:17 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.86 6 comments
Chronology
  1. A certificate request was made for a DNSSEC-signed test domain with CAA response suppression, leading to issuance despite the requester’s expectation.
  2. A Bugzilla case was opened regarding the RapidSSL/Symantec CAA mis-issuance behavior.
  3. The CA ordered revocation and began analysis after confirming the issue.
  4. The CA revoked the problematic certificate(s) and continued root-cause analysis.
  5. The CA installed a patch to stop treating a successful empty CAA fetch at the TLD/PSL as permission to issue.
  6. The CA applied a patch to fix CAA record checking.
  7. Mozilla marked the bug resolved after confirming completion of actions and answered questions.
Thread Activity
  1. Scheitle representative — Reported that a certificate was issued for a DNSSEC-signed domain with a CAA record even though CAA queries timed out due to suppressed responses, and argued this should not be treated as permission to issue.
  2. DigiCert — Provided DigiCert’s incident report describing how the CA became aware, the timeline of confirmation/revocation/analysis, the cause (incorrect handling of CAA response on timeouts), and the patching and revocation actions taken.
  3. Mozilla representative — Noted a discrepancy in the incident report text about additional certificates being found and that the field appeared not to be correctly filled in.
  4. Scheitle representative — Acknowledged the incident response and said they would occasionally retest with a new domain.
  5. DigiCert — Corrected the earlier statement, saying the additional certs were zero and that five total certs were found.
  6. Fastly representative — Marked the bug resolved, stating that all actions were completed and questions answered.
Participants
Scheitle representative DigiCert Mozilla representative Fastly representative
Similar Local Cases
#1413761 RESOLVED Ca Certificate Compliance Opened 2017-11-02 · Closed 2023-02-22 · 96% similar
DigiCert / Symantec: EV JOI Issue
#1438216 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-02-14 · Closed 2022-11-14 · 95% similar
DigiCert: Incorrectly issued EV Certificate
#1447192 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-20 · Closed 2023-02-22 · 95% similar
DigiCert: Onion Certs
#1445857 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-15 · Closed 2023-02-22 · 88% similar
DigiCert: Mis-issuance of certificate with https in CN/SAN
#1451446 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-04-04 · Closed 2023-02-22 · 88% similar
DigiCert / ABB: greater than 825 day cert issuance
#1465600 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-30 · Closed 2023-02-22 · 87% similar
DigiCert: Invalid Country Code Issuance
#1727963 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-08-28 · Closed 2023-02-22 · 87% similar
DigiCert: Truncation of Registration Number
#1827772 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-04-13 · Closed 2023-05-04 · 87% similar
DigiCert: Org-JOI type mismatch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action