DigiCert CAA checking issue caused issuance when the internal CAA service was unreachable
DigiCert reported that its internal CAA record checking service had a bug that allowed certificate issuance when the service was unreachable and timed out. DigiCert said QA discovered the issue on 2019-04-29 while testing another feature, and the same-day fix changed issuance so requests are rejected if no response is received from the CAA checking service. The incident report stated that 1053 certificates were issued without checking CAA records between 2017-09-09 and 2019-04-16, and that 16 of those would fail CAA checks if re-issued today. DigiCert later said it would revoke all impacted certificates except a small number used on critical infrastructure where the domain operator confirmed no CAA record existed at issuance and none exists now. The thread also records follow-up remediation, including training, added alerts, unit tests, and additional checks to confirm CAA checks are performed and recorded. The bug was eventually marked RESOLVED/FIXED, and DigiCert later asked for the bug to be closed.
- CAA checking requirement was in effect
- First affected certificate was issued without checking CAA records
- Last affected certificate was issued without checking CAA records
- DigiCert QA discovered the CAA timeout issue and applied a fix the same day
- DigiCert generated a report identifying 1053 affected certificates
- DigiCert said it would revoke nearly all impacted certificates, with limited exceptions for critical infrastructure
- DigiCert said the rollout had completed and the bug could be closed
- DigiCert — Opened the bug with an incident report describing the CAA timeout issue, the affected certificate count, and the initial remediation steps.
- Fastly representative — Asked for clarification on how the affected count was determined, whether the 16 certificates were still valid, and why the root cause analysis lacked detail.
- DigiCert — Confirmed the count came from logs, said the 16 certificates were still valid, and explained that DigiCert only checked CAA prior to issuance.
- DigiCert — Clarified that the code review had occurred but the reviewer misunderstood the CAA requirements, and said DigiCert would revoke nearly all impacted certificates.
- DigiCert — Posted a revised incident report and additional remediation steps, including training, alerts, and new tests.
- DigiCert — Provided a timeline for the planned remediation items, including completion dates for the new checks.
- DigiCert — Confirmed that remediation items #2 and #3 had been deployed.
- DigiCert — Said redundant checks were in place and the APIs were done, with integration still pending.
- DigiCert — Said the rollout had completed and the bug could be closed.
- DigiCert — Requested that the bug be closed if there were no further questions.