Camerfirma: Potential mis-issuance based on CAA records (CAA checking bypassed)
The case concerns a potential mis-issuance by Camerfirma where CAA records indicated that issuance was not permitted. Quirin Scheitle opened the bug after observing that Camerfirma appeared not to have checked CAA records for the affected certificate, and asked whether CAA checking was bypassed and what response (if any) was received. Camerfirma’s representative stated that Camerfirma bypassed CAA checking for the issuance based on a sentence in the BR that they interpreted as making CAA checking optional when a CT pre-certificate was created and logged, and they acknowledged this was a misunderstanding. Camerfirma reported that the affected certificate was already revoked on 28/Nov/2017 and that it no longer appeared on misissued.com/batch/32. They also stated that CAA check control had been activated in all their RAs. Gerv asked for clarification and a timeline, and Camerfirma further explained that they thought CT already performed the CAA checking. The bug was closed out by Wendy Thayer as the certificate had been revoked and no further actions were pending.
- An AC Camerfirma-issued certificate was logged with issuance times that corresponded to CAA records for am-hosting.de.
- The affected certificate was revoked by Camerfirma.
- The bug was closed out as the certificate was revoked and no further actions were pending.
- Scheitle representative — Filed the bug, stating Camerfirma appeared not to have checked CAA records and asking whether CAA checking was bypassed and what response was received.
- AC Camerfirma, S.A. — Explained that Camerfirma bypassed CAA checking due to a misunderstanding of BR wording, and stated the affected certificate was revoked on 28/Nov/2017 and that CAA check control was activated in all RAs.
- Mozilla representative — Requested clarification on what Camerfirma actually did regarding CAA checking and asked for a timeline of events.
- Scheitle representative — Noted that Camerfirma’s interpretation could be read as CT logging removing the need for CAA checking, pointing to the BR sentence wording.
- Mozilla representative — Pressed for clarification on how Camerfirma interpreted the last clause of the BR sentence about CAA being checked.
- AC Camerfirma, S.A. — Acknowledged confusion around the word “optional,” and stated they believed CT already performed the checking, apologizing for the misunderstanding.
- Fastly representative — Closed the case, stating the certificate had been revoked and no further actions were pending.