← Start Commercial (StartCom) Ltd. cases
Bugzilla #1409760
Certificate Misissuance
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
RESOLVED
WONTFIX
Start Commercial (StartCom) Ltd.
AI Summary
The case involves StartCom issuing a certificate for a domain (www.gazebear.online) that was incorrectly validated due to a CNAME record pointing to another domain with a restrictive CAA record. Despite communication with StartCom, the root cause of the misissuance was not identified initially. However, subsequent updates indicated that the issue was resolved with the installation of a new EJBCA release. Ultimately, StartCom announced its exit from the CA business.
Chronology
- User reported CAA misissuance to StartCom.
- StartCom confirmed that the issue was fixed after system updates.
- StartCom announced exit from the CA business.
Participants
Quirin Scheitle
Iñigo
Gerv
External References
Similar Local Cases
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Asseco DS / Certum: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
Asseco DS / Certum: CAA mis-issuance on critical flag and unknown CAA tag
StartCom's key for bogus www.mozilla.com certificate should be destroyed
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone