← DigiCert cases
Bugzilla #1420861 Certificate Problem Report

DigiCert / Thawte: CAA check dispute for mixed wildcard and non-wildcard SAN

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by Quirin Scheitle to report what he believed was a potential CAA mis-issuance involving a certificate with both a wildcard SAN (*.trnava-vuc.sk) and a non-wildcard SAN (trnava-vuc.sk). Quirin suggested that Thawte may have validated CAA for the wildcard SAN and then added the base domain SAN without a further CAA check, and he asked whether CAA checking was bypassed or what CAA response was received. DigiCert’s Jeremy Rowley responded that the issuance was not mis-issued and stated that the CAA record returned empty, providing CAA log excerpts showing “CAA record not found” for both trnava-vuc.sk and *.trnava-vuc.sk. Mozilla’s Gerv noted that this appears to be a “he said, she said” situation because the reporter does not own the domain and cannot make normative statements about DNS state at any particular time, and he accepted the CA’s logs as evidence in such cases. Quirin agreed with the discussion and welcomed the log excerpt, noting he reported it because similar wildcard/non-wildcard combinations had issues at other CAs. The bug was resolved with resolution set to INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 11:17 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.86 5 comments
Chronology
  1. Quirin Scheitle filed a CA Program bug reporting a suspected CAA mis-issuance for a certificate containing mixed wildcard and non-wildcard SAN entries.
  2. DigiCert provided CAA log excerpts asserting the CAA record was not found for both the wildcard and base domain during issuance.
  3. Mozilla and the reporter discussed the limitations of CAA checking and the need for transparency via log-operator checks.
Thread Activity
  1. Scheitle representative — Quirin filed the bug, describing a suspected CAA checking issue for a certificate with both *.trnava-vuc.sk and trnava-vuc.sk SANs and asking whether CAA checking was bypassed or what CAA response was received.
  2. DigiCert — Jeremy Rowley said the case was not mis-issued and provided CAAV2CheckService log excerpts showing “CAA record not found” for trnava-vuc.sk and *.trnava-vuc.sk.
  3. Mozilla representative — Gerv stated he would accept the CA logs as evidence given the reporter does not own the domain, and characterized the situation as “he said, she said.”
  4. DigiCert — Jeremy agreed it is a “he said/she said” situation and discussed a proposal to shift CAA record checking to log operators to improve transparency and flag potential mis-issuance.
  5. Scheitle representative — Quirin agreed with the discussion, said he reported it due to similar issues at other CAs, and offered help with the proposal.
Participants
Scheitle representative DigiCert Mozilla representative
Similar Local Cases
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 58% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 54% similar
DigiCert: TERENA: No localityName in EV precert
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 54% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 53% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1518555 RESOLVED Certificate Misissuance Opened 2019-01-08 · Closed 2023-02-22 · 52% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm
#1896462 RESOLVED Certificate Problem Report Opened 2024-05-13 · Closed 2024-06-01 · 52% similar
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
#1262610 RESOLVED Ca Certificate Compliance Opened 2016-04-06 · Closed 2023-02-22 · 52% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 51% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action