← Asseco Data Systems S.A. cases
Bugzilla #1409764 Ca Certificate Compliance Certificate Misissuance

Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag

RESOLVED FIXED Asseco Data Systems S.A.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports a certificate mis-issuance involving Certum (Asseco Data Systems S.A.) and DNS CAA records. The reporter set up a test domain with two CAA records: one permitting issuance for the issuer and another using the critical flag (128) with an unknown CAA tag, which should deny issuance. Despite this, Certum issued a certificate. The reporter provided the certificate link and noted that Certum confirmed the event as mis-issuance but had not yet confirmed a root cause at the time of the initial report. Certum’s representative stated that the verification outcome depended on the order of CAA records returned by the DNS zone, and that a patch was ready to be implemented on October 23, 2017. A later update from the CA representative indicated that the problem was resolved. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:36 UTC Revised: 2026-06-16 18:01 UTC Confidence: 0.88 4 comments
Chronology
  1. Certum issued a certificate for a test domain despite CAA records that should have denied issuance due to a critical flag and unknown tag.
  2. A patch intended to address the CAA verification behavior was scheduled to be implemented.
  3. The CA reported that the problem was resolved.
Thread Activity
  1. Scheitle representative — Reported that Certum issued a certificate even though CAA records included a critical flag (128) and an unknown tag, and provided a crt.sh certificate link and DNS zone reference.
  2. Assecods representative — Explained that the order of CAA records in the DNS response affected verification, and stated that a patch was ready for implementation on October 23, 2017.
  3. Mozilla representative — Asked Arkadiusz for an update on the case.
  4. Assecods representative — Confirmed that the problem was resolved.
Participants
Scheitle representative Assecods representative Mozilla representative
Similar Local Cases
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 100% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409766 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 96% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 90% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1435770 RESOLVED Ca Certificate Compliance Opened 2018-02-05 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1451228 RESOLVED Ca Certificate Compliance Opened 2018-04-04 · Closed 2023-02-22 · 89% similar
Asseco DS / Certum: EV certificate mis-issue
#1823040 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-03-17 · Closed 2023-05-19 · 89% similar
Asseco DS / Certum: Cross-certificate with wrong policy identifier
#1550575 RESOLVED Certificate Misissuance Opened 2019-05-09 · Closed 2023-02-22 · 80% similar
Asseco DS / Certum: commonName not from subjectAltName entries
#1853663 RESOLVED Certificate Misissuance Opened 2023-09-18 · Closed 2024-05-09 · 80% similar
Asseco DS / Certum: SMIME certificates with wrong organizationIdentifier

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action