Globalsign / AlphaSSL: CAA mis-issuance on mixed wildcard/non-wildcard SAN
This case concerns an AlphaSSL certificate issued by GlobalSign that includes a mixed wildcard and non-wildcard DNS SAN ("*.invinsec.com" and "invinsec.com"). The reporter alleged that GlobalSign likely mis-issued because CAA was validated for the wildcard SAN but the base domain SAN was added without a further CAA check, and that the base domain was not permitted for GlobalSign at the time. GlobalSign’s CAA logs were provided, stating that at issuance time there were no issuewild entries and that "digicert.com", "globalsign.com", "letsencrypt.org", and "rapidssl.com" were listed as issue entries. The reporter responded that their DNS history was compiled from multiple scans at different times and argued the CAA configuration may have changed briefly, suggesting the issue could be a false positive. Mozilla’s Gerv resolved the bug as INVALID. No further remediation steps are described in the thread.
- GlobalSign (AlphaSSL) issued a certificate for *.invinsec.com and invinsec.com.
- The bug was filed alleging CAA mis-issuance for the mixed wildcard/non-wildcard SAN.
- GlobalSign provided CAA log details and the reporter replied with scan-timestamp evidence; Mozilla resolved the bug as INVALID.
- Scheitle representative — Filed the bug alleging GlobalSign likely mis-issued by validating CAA for the wildcard SAN but adding the base domain SAN without a further CAA check, and provided the certificate and related discussion links.
- Mozilla representative — Assigned the bug to the GlobalSign representative.
- Community commenter — Asked how the DNS history was created because GlobalSign’s CAA logs showed no issuewild entries and listed multiple issuers as issue entries.
- Scheitle representative — Explained the DNS history was compiled from multiple scans at different times and argued the CAA configuration may have changed briefly, making the report potentially a false positive.
- Mozilla representative — Resolved the bug as INVALID.