← Internet Security Research Group cases
Bugzilla #1462735
Certificate Problem Report
Let's Encrypt: Case-sensitive CAA tag processing
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt faced an incident where it improperly handled CAA records with mixed case tags, leading to mis-issuance of certificates. The issue was reported on May 18, 2018, and was confirmed quickly. A fix was developed and deployed within hours, and issuance of new certificates was temporarily disabled to prevent further mis-issuance. Post-incident actions included improving logging and revoking affected certificates. The incident was resolved with no responses from account contacts regarding the identified mis-issued certificates.
Chronology
- Incident reported regarding case-sensitive CAA tag processing.
- Fix developed and deployed to staging environment.
- Issuance of new certificates disabled to prevent further mis-issuance.
- Post-incident actions completed, including revocation of affected certificates.
Participants
Wayne Thayer
Josh Aas
External References
Similar Local Cases
Let's Encrypt: OCSP "unauthorized" responses
Let's Encrypt: Improper encoding of wildcard certificates
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
Let's Encrypt: Non-BR-Compliant Certificate Issuance
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Incomplete revocation for CAA rechecking bug