← AC Camerfirma, S.A. cases
Bugzilla #1420871 Certificate Misissuance

Camerfirma: Potential Mis-Issuance based on CAA records

RESOLVED FIXED AC Camerfirma, S.A.
AI Summary

The case involves Camerfirma's potential mis-issuance of a certificate due to a failure to check CAA records. It was determined that the issuance bypassed required CAA checks, which led to the certificate being revoked on November 28, 2017. The misunderstanding stemmed from an interpretation of the BR that suggested CAA checking was optional under certain conditions. Following discussions, Camerfirma acknowledged the error and has since activated CAA check controls in all their Registration Authorities.

Model: gpt-4o-mini Generated: 2026-06-13 17:40 UTC Confidence: 1.00
Chronology
  1. Bug filed regarding potential mis-issuance.
  2. Affected certificate revoked.
  3. Camerfirma acknowledges misunderstanding of CAA requirements.
  4. Case closed as no further actions are pending.
Participants
Quirin Scheitle Ramiro Muñoz Muñoz Gervase Markham
Similar Local Cases
#1405815 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 65% similar
Camerfirma: Certs issued with same issuer and serial number
#1420860 RESOLVED Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 58% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409735 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2024-05-09 · 55% similar
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
#1420766 RESOLVED Certificate Misissuance Opened 2017-11-26 · Closed 2024-05-09 · 54% similar
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1409766 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2023-02-22 · 54% similar
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1481862 RESOLVED Certificate Misissuance Opened 2018-08-08 · Closed 2023-02-22 · 49% similar
Camerfirma: MULTICERT organizationName Too Long
#1431164 RESOLVED Certificate Misissuance Opened 2018-01-17 · Closed 2023-02-22 · 49% similar
Camerfirma: Non-BR-Compliant Issuance - Non-printable characters in OU field
#1443857 RESOLVED Certificate Misissuance Opened 2018-03-07 · Closed 2023-02-22 · 48% similar
Camerfirma: Non-BR-Compliant Issuance - DNSName is empty

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action