← Certigna cases
Bugzilla #1485413 Ca Certificate Compliance

Certigna: Issuance without respecting CAA records

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Certigna issuing certificates without respecting DNS CAA records as required by Mozilla Baseline Requirements. The trigger was a report by Wayne Thayer (Fastly) citing BR section 3.2.2.8, which requires CAs to respect RFC 6844 CAA records when issuing certificates. Certigna confirmed that its CPS language had allowed issuance based on a signed authorization even when the applicant had not updated CAA, and it stated that it had not updated its documents accordingly. Certigna also stated that it had controls and monitoring in place to block requests based on CAA alerts, and that it would update its CP/CPS documents. Certigna provided an incident report for the issue of one certificate without DNS CAA authorization in the mozilla.dev.security.policy forum thread referenced in the bug. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:53 UTC Revised: 2026-06-16 18:21 UTC Confidence: 0.86 6 comments
Chronology
  1. Wayne Thayer reported that Certigna issued certificates without respecting DNS CAA records, citing BR section 3.2.2.8.
  2. Certigna confirmed its CPS interpretation and discussed remediation and CP/CPS updates.
  3. Certigna posted an incident report for a certificate issued without DNS CAA authorization.
  4. Questions were answered in the referenced mozilla.dev.security.policy forum thread.
  5. The bug was resolved as FIXED.
Thread Activity
  1. Fastly representative — Wayne Thayer cited BR section 3.2.2.8 and asked Certigna to identify and remediate misissued certificates and provide an incident report, referencing Certigna’s CPS language and a Mozilla wiki incident-report process.
  2. Dhimyotis representative — Josselin Allemandou confirmed the issue was due to CP/CPS not being updated, stated that controls to block CAA alert cases existed, and offered to update CP/CPS before the end of the week.
  3. Dhimyotis representative — Josselin Allemandou clarified that the CP/CPS consent interpretation was based on a signed legal-representative document, while Certigna still set up controls and monitoring, and only failed to regularize the CP/CPS wording.
  4. Dhimyotis representative — Josselin Allemandou posted an incident report about one certificate without DNS CAA authorization, linking to the mozilla.dev.security.policy forum thread.
  5. Fastly representative — Wayne Thayer stated that questions were answered in the referenced mozilla.dev.security.policy thread.
Participants
Fastly representative Dhimyotis representative
Similar Local Cases
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 69% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1443733 RESOLVED Ca Certificate Compliance Opened 2018-03-07 · Closed 2023-02-22 · 69% similar
SwissSign: Cert issued with a to long validity period
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 69% similar
Certigna: TLS certificates with Basic constraint non-critical
#1435770 RESOLVED Ca Certificate Compliance Opened 2018-02-05 · Closed 2023-02-22 · 69% similar
Asseco DS / Certum: Non-BR-Compliant Issuance - Debian Weak Keys
#1443857 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-07 · Closed 2023-02-22 · 69% similar
Camerfirma: Non-BR-Compliant Issuance - DNSName is empty
#1451446 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-04-04 · Closed 2023-02-22 · 68% similar
DigiCert / ABB: greater than 825 day cert issuance
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 68% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#1420860 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 68% similar
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action