← Internet Security Research Group cases
Bugzilla #1462735 Ca Certificate Compliance Certificate Misissuance

Let's Encrypt: Case-sensitive CAA tag processing

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that Let’s Encrypt improperly handled CAA records with mixed-case tag values, which resulted in mis-issuance under the CA/B Baseline Requirements. The issue was triggered when Let’s Encrypt received an incident report to its c**********s@letsencrypt.org contact address at 12:45 UTC. The reporter noted that RFC 6844 specifies case-insensitive matching of tag values, but Let’s Encrypt’s CAA validation processed tags case-sensitively, causing non-lowercase tags to be ignored. Let’s Encrypt confirmed the problem, developed and reviewed a fix within an hour, deployed it to staging, disabled new certificate issuance in production, and then deployed the fix to production. Let’s Encrypt revoked one certificate identified by the reporter as issued in violation of the CAA RFC. Later, Let’s Encrypt implemented CAA logging improvements, scanned CAA records for the prior 90 days, identified 11 certificates that would not have been issued, sent emails to ACME account contacts with four days to respond, revoked the remaining 8 after no responses, and considered the incident closed.

Model: gpt-5.4-nano Generated: 2026-06-13 17:48 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 3 comments
Chronology
  1. Let’s Encrypt received an incident report about mixed-case CAA tag handling that led to mis-issuance.
  2. Let’s Encrypt deployed a fix, disabled production issuance temporarily, and revoked the certificate identified by the reporter.
  3. Let’s Encrypt completed CAA logging improvements and a scan, revoked affected certificates, and closed the incident.
Thread Activity
  1. Community commenter — Josh Aas reported that mixed-case CAA tags were processed case-sensitively, leading to CAA validation ignoring non-lowercase tags; he described the fix timeline, production issuance disablement, and revocation of the reporter-identified certificate.
  2. Fastly representative — Wayne Thayer asked Josh to update the bug with the status of the proposed remediation actions.
  3. Kflag representative — Josh Aas stated that CAA logging improvements were committed, a scan identified 11 certificates that would not have been issued, emails were sent to ACME account contacts with four days to respond, three certificates expired during the response window, the remaining eight were revoked, and the incident was closed.
Participants
Fastly representative Kflag representative
Similar Local Cases
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 99% similar
Let's Encrypt: CAA Misissuances
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 97% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 90% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 81% similar
Let's Encrypt: Duplicate Serial Numbers
#1789521 RESOLVED Certificate Misissuance Opened 2022-09-06 · Closed 2024-05-09 · 78% similar
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 78% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 78% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action