Certigna: Issuance without respecting CAA records
This case concerns Certigna issuing certificates without respecting DNS CAA records as required by Mozilla Baseline Requirements. The trigger was a report by Wayne Thayer (Fastly) citing BR section 3.2.2.8, which requires CAs to respect RFC 6844 CAA records when issuing certificates. Certigna confirmed that its CPS language had allowed issuance based on a signed authorization even when the applicant had not updated CAA, and it stated that it had not updated its documents accordingly. Certigna also stated that it had controls and monitoring in place to block requests based on CAA alerts, and that it would update its CP/CPS documents. Certigna provided an incident report for the issue of one certificate without DNS CAA authorization in the mozilla.dev.security.policy forum thread referenced in the bug. The bug is marked RESOLVED with resolution FIXED.
- Wayne Thayer reported that Certigna issued certificates without respecting DNS CAA records, citing BR section 3.2.2.8.
- Certigna confirmed its CPS interpretation and discussed remediation and CP/CPS updates.
- Certigna posted an incident report for a certificate issued without DNS CAA authorization.
- Questions were answered in the referenced mozilla.dev.security.policy forum thread.
- The bug was resolved as FIXED.
- Fastly representative — Wayne Thayer cited BR section 3.2.2.8 and asked Certigna to identify and remediate misissued certificates and provide an incident report, referencing Certigna’s CPS language and a Mozilla wiki incident-report process.
- Dhimyotis representative — Josselin Allemandou confirmed the issue was due to CP/CPS not being updated, stated that controls to block CAA alert cases existed, and offered to update CP/CPS before the end of the week.
- Dhimyotis representative — Josselin Allemandou clarified that the CP/CPS consent interpretation was based on a signed legal-representative document, while Certigna still set up controls and monitoring, and only failed to regularize the CP/CPS wording.
- Dhimyotis representative — Josselin Allemandou posted an incident report about one certificate without DNS CAA authorization, linking to the mozilla.dev.security.policy forum thread.
- Fastly representative — Wayne Thayer stated that questions were answered in the referenced mozilla.dev.security.policy thread.