← Asseco Data Systems S.A. cases
Bugzilla #1420860
Certificate Misissuance
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
RESOLVED
FIXED
Asseco Data Systems S.A.
AI Summary
The case involves a misissuance of a certificate by Certum for a domain with mixed wildcard and non-wildcard DNS names. The issue arose from a misunderstanding of CAA record validation, leading to the issuance of a certificate without proper checks. Certum acknowledged the misinterpretation of RFC 6844, which contributed to the error. Ultimately, the case was resolved with Certum asserting that the certificate was issued correctly based on the validation conducted on the date of issuance, despite the confusion regarding CAA records.
Chronology
- Bug reported regarding CAA misissuance.
- Certum acknowledges improper processing of CAA records.
- Case resolved as FIXED despite Certum's assertion of no misissuance.
Participants
Quirin Scheitle
Arkadiusz Ławniczak
Gervase Markham
W. Thayer
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
Asseco DS / Certum: EV certificate mis-issue
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Camerfirma: Potential Mis-Issuance based on CAA records
Asseco DS / Certum: EV Certificates issued with wrong Business Category