← Asseco Data Systems S.A. cases
Bugzilla #1409766 Certificate Misissuance

Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record

RESOLVED FIXED Asseco Data Systems S.A.
AI Summary

This case involved a misissuance of a certificate by Certum for the domain www.gazebear.online, which was a CNAME pointing to a domain with a restrictive CAA record. Certum issued the certificate despite the CAA record indicating that issuance should not occur. The issue was reported on October 16, 2017, and Certum acknowledged problems with CAA checking for subdomains. They implemented a fix and improved their CAA validation process, which was fully operational by September 11, 2018. The case was resolved with no further misissuances detected.

Model: gpt-4o-mini Generated: 2026-06-13 17:37 UTC Confidence: 0.90
Chronology
  1. Issue reported to Certum
  2. Automated CAA verification improvements deployed
Participants
Quirin Scheitle Wojciech Trapczyński Gervase Markham Arkadiusz Lawniczak Wayne Thayer Ryan Sleevi
Similar Local Cases
#1611458 RESOLVED Certificate Misissuance Opened 2020-01-24 · Closed 2023-02-22 · 73% similar
Asseco DS / Certum: Invalid value in SAN dNSName
#1420860 RESOLVED Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 70% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409764 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 60% similar
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
#1435770 RESOLVED Certificate Misissuance Opened 2018-02-05 · Closed 2023-02-22 · 59% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1600301 RESOLVED Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 57% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 57% similar
NetLock: CN not in SAN
#1428877 RESOLVED Certificate Misissuance Opened 2018-01-08 · Closed 2023-02-22 · 57% similar
SwissSign: Invalid DNSName in SAN
#1409735 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2024-05-09 · 57% similar
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action