StartCom: CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
The case concerns a certificate issuance experiment where a test domain is DNSSEC-signed and contains a CAA record, but the server was configured not to reply to CAA queries, causing CAA lookup timeouts. The reporter stated that, because the zone is validly signed, the lookup failure should not be interpreted as permission to issue, citing CAB Ballot 187. StartCom communicated that it installed EJBCA 6.10.0 and believed the error was fixed, and later planned further updates after Primekey released patch 6.10.0.1 with CAA test suites checked for correct handling. Mozilla noted that StartCom was exiting the CA business. The bug was ultimately marked RESOLVED with resolution INVALID. No further root cause was identified in the thread.
- Bug opened regarding a CAA lookup timeout on a DNSSEC-signed zone during a certificate issuance experiment.
- StartCom reported updating EJBCA and believed the CAA handling error was fixed, with additional patching planned.
- Mozilla noted StartCom was exiting the CA business.
- Scheitle representative — Reported that a DNSSEC-signed zone with a CAA record timed out on CAA queries due to server non-response, and argued the failure must not be treated as permission to issue (citing CAB Ballot 187).
- WoSign CA Limited — Said StartCom installed EJBCA 6.10.0 and that the error appeared fixed, and that they would update further after EJBCA 6.10.0.1 was released.
- Mozilla representative — Noted that StartCom is exiting the CA business.