← GlobalSign nv-sa cases
Bugzilla #1420766
Certificate Misissuance
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
RESOLVED
INVALID
GlobalSign nv-sa
AI Summary
This case involves a mis-issuance by GlobalSign for a certificate that included both wildcard and non-wildcard DNS names in the Subject Alternative Name (SAN). The issue arose when GlobalSign validated the CAA record for the wildcard SAN but did not perform a subsequent check for the base domain. As a result, the base domain was incorrectly added, leading to the mis-issuance. The case was ultimately resolved as INVALID after discussions highlighted discrepancies in CAA logs and DNS history.
Chronology
- Initial bug filed regarding CAA mis-issuance.
- Bug resolved as INVALID.
Participants
Quirin Scheitle
Linus Hallberg
Gervase Markham
Douglas Beattie
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Camerfirma: Potential Mis-Issuance based on CAA records
GlobalSign: EV certificate with wildcard domain in common name and SAN
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
GlobalSign: 4 Misissued certificates with invalid CN