DigiCert / Thawte: CAA check dispute for mixed wildcard and non-wildcard SAN
The bug was opened by Quirin Scheitle to report what he believed was a potential CAA mis-issuance involving a certificate with both a wildcard SAN (*.trnava-vuc.sk) and a non-wildcard SAN (trnava-vuc.sk). Quirin suggested that Thawte may have validated CAA for the wildcard SAN and then added the base domain SAN without a further CAA check, and he asked whether CAA checking was bypassed or what CAA response was received. DigiCert’s Jeremy Rowley responded that the issuance was not mis-issued and stated that the CAA record returned empty, providing CAA log excerpts showing “CAA record not found” for both trnava-vuc.sk and *.trnava-vuc.sk. Mozilla’s Gerv noted that this appears to be a “he said, she said” situation because the reporter does not own the domain and cannot make normative statements about DNS state at any particular time, and he accepted the CA’s logs as evidence in such cases. Quirin agreed with the discussion and welcomed the log excerpt, noting he reported it because similar wildcard/non-wildcard combinations had issues at other CAs. The bug was resolved with resolution set to INVALID.
- Quirin Scheitle filed a CA Program bug reporting a suspected CAA mis-issuance for a certificate containing mixed wildcard and non-wildcard SAN entries.
- DigiCert provided CAA log excerpts asserting the CAA record was not found for both the wildcard and base domain during issuance.
- Mozilla and the reporter discussed the limitations of CAA checking and the need for transparency via log-operator checks.
- Scheitle representative — Quirin filed the bug, describing a suspected CAA checking issue for a certificate with both *.trnava-vuc.sk and trnava-vuc.sk SANs and asking whether CAA checking was bypassed or what CAA response was received.
- DigiCert — Jeremy Rowley said the case was not mis-issued and provided CAAV2CheckService log excerpts showing “CAA record not found” for trnava-vuc.sk and *.trnava-vuc.sk.
- Mozilla representative — Gerv stated he would accept the CA logs as evidence given the reporter does not own the domain, and characterized the situation as “he said, she said.”
- DigiCert — Jeremy agreed it is a “he said/she said” situation and discussed a proposal to shift CAA record checking to log operators to improve transparency and flag potential mis-issuance.
- Scheitle representative — Quirin agreed with the discussion, said he reported it due to similar issues at other CAs, and offered help with the proposal.