← DigiCert cases
Bugzilla #1409735 Certificate Misissuance

DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone

RESOLVED DigiCert
AI Summary

This case involves a mis-issuance of a certificate by DigiCert for a domain that was DNSSEC-signed but had a misconfigured server that did not respond to CAA queries. The certificate was issued despite the failure to retrieve the necessary CAA record, which should have prevented issuance according to CAB guidelines. Following the report, DigiCert confirmed the issue, revoked the certificate, and implemented a patch to prevent similar occurrences in the future.

Model: gpt-4o-mini Generated: 2026-06-13 11:17 UTC Confidence: 0.95
Chronology
  1. Complaint received regarding certificate issuance
  2. Issue confirmed and revocation ordered
  3. Certificate revoked
  4. Patch applied to fix CAA record checking
Participants
Quirin Scheitle Steven Medin Jeremy Rowley Gervase Markham W. Thayer
Similar Local Cases
#1397969 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 66% similar
DigiCert / Inteso San Paulo: Double dot characters
#1420860 RESOLVED Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 65% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1313872 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 64% similar
SHA-1 issuance by DigiCert roots
#1531817 RESOLVED Certificate Misissuance Opened 2019-03-01 · Closed 2023-02-22 · 61% similar
DigiCert: in-addr.arpa Misissuance
#1500621 RESOLVED Certificate Misissuance Opened 2018-10-19 · Closed 2023-02-22 · 61% similar
DigiCert: Internal Domain Name cert mis-issuance
#1353827 RESOLVED Certificate Misissuance Opened 2017-04-05 · Closed 2023-02-22 · 60% similar
DigiCert: DigiCert issued cert with CN too long
#1335132 RESOLVED Certificate Misissuance Opened 2017-01-30 · Closed 2023-02-22 · 60% similar
DigiCert: Verizon mis-issued test certificates
#1684442 RESOLVED Certificate Misissuance Opened 2020-12-29 · Closed 2023-02-22 · 59% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action