Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
This case involves Asseco Data Systems S.A. (Certum) disclosing a misissuance incident where a certificate was incorrectly issued for a domain due to improper CAA validation. The issue was reported by Quirin Scheitle on October 16, 2017, after which Certum acknowledged the problem and initiated an audit of all issued certificates. They confirmed that the misissue was caused by a flaw in their CAA validation process, particularly for domains with a 'www' prefix and CNAME records. Certum implemented corrective measures, including a new validation module, and revoked the misissued certificate on November 7, 2017. The incident was resolved with the deployment of the updated CAA validation system on September 11, 2018.
- Certificate issued incorrectly due to CAA misvalidation.
- Issue reported to Certum by Quirin Scheitle.
- Certum revoked the misissued certificate.
- Certum deployed a fixed CAA validation module.
- Scheitle representative — Reported a misissuance incident involving a CAA record.
- Assecods representative — Confirmed issues with CAA checking and outlined a plan for improvements.
- Asseco Data Systems S.A. — Announced deployment of the automated CAA verification system.
- Fastly representative — Confirmed that remediation is complete and resolved the case.