Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
This case concerns a potential misissuance by Certum related to the handling of CAA records for a certificate that included both wildcard and non-wildcard DNS names in its Subject Alternative Name (SAN). The issue was triggered by a report indicating that Certum may have bypassed CAA checks when issuing the certificate for the domain cyberbajt.pl. After investigation, Certum acknowledged that there was a misinterpretation of RFC 6844 regarding CAA validation. However, they later clarified that the certificate was issued correctly based on the CAA records available at the time of issuance. The case was ultimately resolved as 'FIXED' despite initial concerns about misissuance.
- Certificate issued for cyberbajt.pl with mixed wildcard and non-wildcard SAN.
- Scheitle representative — Filed a bug regarding potential CAA misissuance by Certum.
- Assecods representative — Confirmed improper processing of CAA records for wildcard certificates.
- Assecods representative — Clarified that the certificate was issued correctly based on the CAA records at the time.
- Fastly representative — Resolved the case as FIXED due to lack of evidence for misissuance.