← Asseco Data Systems S.A. cases
Bugzilla #1409764
Certificate Misissuance
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
This case involves a mis-issuance of a certificate by Certum due to incorrect handling of CAA records. The user reported that a critical flag was set on an unknown CAA tag, which should have prevented the issuance. Certum acknowledged the mis-issuance but did not confirm the root cause initially. The issue was resolved with a patch ready for implementation shortly after the report.
Chronology
- User reported mis-issuance to Certum.
- Discussion on the verification process and patch readiness.
- Confirmation that the problem is resolved.
Participants
Quirin Scheitle
Arkadiusz Ławniczak
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
Asseco DS / Certum: EV certificate mis-issue
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Camerfirma: Potential Mis-Issuance based on CAA records