DigiCert/RapidSSL: CAA mis-issuance due to CAA lookup timeout on DNSSEC-signed zone
The case describes a certificate mis-issuance involving RapidSSL (Symantec legacy systems) where a certificate was issued despite the requester’s claim that CAA permission should not have been granted. The requester reported that the test domain was DNSSEC-signed and had a CAA record, but the server was configured not to reply to CAA queries, causing CAA lookups to time out. The bug thread states that the lookup failure must not be treated as permission to issue when DNSSEC validation is present, referencing CAB Ballot 187. DigiCert’s incident report states that the CA confirmed the issue, ordered revocation, and started analysis, then revoked the affected certificate(s) on 2017-10-19/2017-10-20. The CA determined the cause as incorrect handling of CAA response when CAA fetch timed out at the base domain and software rules improperly treated an empty set from the TLD or public suffix as permission to issue. DigiCert states it wrote and applied a patch to correct DNSSEC record checking (with a later identifier issue impacting one certificate), installed a change to stop treating a successful empty set fetch at the TLD/PSL as permission to issue, and applied further investigation after the patch. The thread concludes with a comment from Mozilla marking the bug resolved after actions were completed and questions answered.
- A certificate request was made for a DNSSEC-signed test domain with CAA response suppression, leading to issuance despite the requester’s expectation.
- A Bugzilla case was opened regarding the RapidSSL/Symantec CAA mis-issuance behavior.
- The CA ordered revocation and began analysis after confirming the issue.
- The CA revoked the problematic certificate(s) and continued root-cause analysis.
- The CA installed a patch to stop treating a successful empty CAA fetch at the TLD/PSL as permission to issue.
- The CA applied a patch to fix CAA record checking.
- Mozilla marked the bug resolved after confirming completion of actions and answered questions.
- Scheitle representative — Reported that a certificate was issued for a DNSSEC-signed domain with a CAA record even though CAA queries timed out due to suppressed responses, and argued this should not be treated as permission to issue.
- DigiCert — Provided DigiCert’s incident report describing how the CA became aware, the timeline of confirmation/revocation/analysis, the cause (incorrect handling of CAA response on timeouts), and the patching and revocation actions taken.
- Mozilla representative — Noted a discrepancy in the incident report text about additional certificates being found and that the field appeared not to be correctly filled in.
- Scheitle representative — Acknowledged the incident response and said they would occasionally retest with a new domain.
- DigiCert — Corrected the earlier statement, saying the additional certs were zero and that five total certs were found.
- Fastly representative — Marked the bug resolved, stating that all actions were completed and questions answered.