DigiCert: in-addr.arpa Misissuance
The case concerns a DigiCert incident where a certificate was issued with a SAN FQDN that the requester said they did not control. The initial report was posted to the mozilla.dev.security.policy mailing list by Cynthia Revström, who said the certificate was issued after adding 69.168.110.79.in-addr.arpa to her SAN, and she believed the validation process caused the whole in-addr.arpa to be validated on her account. DigiCert’s Jeremy Rowley explained that a validation agent manually uploaded a WHOIS document that did not match the domain requested closely enough for the mismatch to go unnoticed, which led to an improperly set approval scope; as a result, the validation authorized the account for all certificates with the in-addr.arpa domain. DigiCert revoked the DCV for in-addr.arpa in Cynthia’s account and revoked the identified certificates (including the crt.sh IDs referenced in the thread). In the incident report, DigiCert stated it stopped issuing certificates within in-addr.arpa on 26 Feb 2019 and disabled manual WHOIS document uploads for non-managers on 27 Feb 2019, and it performed a system-wide scan for related cases. The thread later indicates that questions were answered and remediation was complete, and the bug is marked RESOLVED with resolution FIXED.
- DigiCert issued two certificates related to in-addr.arpa (crt.sh IDs 1231235765 and 1231411316).
- DigiCert revoked DCV for in-addr.arpa in the affected account and revoked the identified certificates.
- DigiCert disabled manual WHOIS document uploads for non-managers and performed a system-wide scan for related cases.
- Fastly representative — Wayne Thayer posted Cynthia Revström’s message describing a certificate issuance with an FQDN in the SAN that she said she did not control and linking to the precert and discussion.
- Fastly representative — Jeremy Rowley explained the cause: a validation agent manually uploaded a WHOIS screenshot, improperly set the approval scope, and the validation authorized the account for all in-addr.arpa certificates; he also said manual WHOIS verification was shut down while improvements were investigated.
- DigiCert — Jeremy Rowley posted an incident report detailing the timeline, revocations, issuance stop, process explanation, and remediation steps including disabling manual WHOIS uploads for non-managers.
- Community commenter — Ryan Sleevi said he had no further comments and that remediation appeared complete.
- Fastly representative — Wayne Thayer stated it appears all questions have been answered and remediation is complete.