Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
The case reports a certificate mis-issuance involving Certum (Asseco Data Systems S.A.) and DNS CAA records. The reporter set up a test domain with two CAA records: one permitting issuance for the issuer and another using the critical flag (128) with an unknown CAA tag, which should deny issuance. Despite this, Certum issued a certificate. The reporter provided the certificate link and noted that Certum confirmed the event as mis-issuance but had not yet confirmed a root cause at the time of the initial report. Certum’s representative stated that the verification outcome depended on the order of CAA records returned by the DNS zone, and that a patch was ready to be implemented on October 23, 2017. A later update from the CA representative indicated that the problem was resolved. The bug is marked RESOLVED with resolution FIXED.
- Certum issued a certificate for a test domain despite CAA records that should have denied issuance due to a critical flag and unknown tag.
- A patch intended to address the CAA verification behavior was scheduled to be implemented.
- The CA reported that the problem was resolved.
- Scheitle representative — Reported that Certum issued a certificate even though CAA records included a critical flag (128) and an unknown tag, and provided a crt.sh certificate link and DNS zone reference.
- Assecods representative — Explained that the order of CAA records in the DNS response affected verification, and stated that a patch was ready for implementation on October 23, 2017.
- Mozilla representative — Asked Arkadiusz for an update on the case.
- Assecods representative — Confirmed that the problem was resolved.