← Amazon Trust Services cases
Bugzilla #1746945 Certificate Misissuance Self Reported Incident

Amazon Trust Services: Missing CAA check for test website certificates

RESOLVED FIXED Amazon Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Amazon Trust Services reported that, during an internal self-audit, an engineer identified that a CAA check was missed for certificates issued for its test websites on Dec 8, 2021. The issue arose during a ceremony to revoke intermediates, during which 10 certificates for test websites were created; five were revoked immediately after issuance (test revoke certificates) and five were revoked later (test valid certificates). After reviewing the validation performed on Dec 8, the team determined that a CAA check was required and had been missed. On Dec 17, 2021, Amazon Trust Services revoked the five certificates that would have been used as test valid certificates, and stated that it had stopped. The thread includes discussion that the intermediates used for these test certificates are offline and manual, and that Amazon Trust Services does not operate online intermediates for day-to-day issuance. Mozilla indicated it would close the bug on 14-Jan-2022 unless further items were needed, and Amazon Trust Services confirmed it had no further items planned. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:29 UTC Revised: 2026-06-16 18:06 UTC Confidence: 0.90 6 comments
Chronology
  1. Amazon Trust Services performed an intermediates revocation ceremony and created 10 test website certificates, revoking five immediately after issuance.
  2. Amazon Trust Services reviewed the Dec 8 validation and determined a CAA check was required but had been missed for the test website certificates.
  3. Amazon Trust Services revoked the five test valid certificates for which the CAA check had been missed.
  4. Mozilla planned to close the bug if no further items were needed.
Thread Activity
  1. DigiCert — Reported that an internal self-audit found a missed CAA check for 10 test website certificates created on Dec 8, 2021, and described the subsequent revocation of the five test valid certificates.
  2. Thisisntrocket representative — Suggested using online intermediates/automation to avoid manual validation and input mistakes.
  3. DigiCert — Responded that Amazon Trust Services does not operate online intermediates for day-to-day issuance and that DigiCert operates the intermediates used for day-to-day certificates.
  4. DigiCert — Stated that Amazon Trust Services was monitoring the bug for feedback and had no further action items planned.
  5. Mozilla representative — Said the bug would be closed on 14-Jan-2022 unless additional items needed addressing.
  6. DigiCert — Confirmed there were no further items planned.
Participants
DigiCert Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1914893 RESOLVED Certificate Misissuance Opened 2024-08-26 · Closed 2024-09-18 · 97% similar
Amazon Trust Services: CRL not DER-encoded
#2009525 RESOLVED Self Reported Incident Opened 2026-01-09 · Closed 2026-03-08 · 94% similar
Amazon Trust Services: Additional CRL Characteristics Desired in CP/CPS
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 90% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#1832093 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-05-09 · Closed 2023-06-02 · 87% similar
Asseco DS / Certum: Subordinate certificates with sequential serial number
#1713978 RESOLVED Certificate Misissuance Opened 2021-06-02 · Closed 2023-02-22 · 87% similar
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
#1731586 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Opened 2021-09-20 · Closed 2023-02-22 · 86% similar
SwissSign: Certificate with key length 16258
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 84% similar
GlobalSign: Invalid countryName
#1726333 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-08-18 · Closed 2023-02-22 · 84% similar
Network Solutions: All test CA test website certificates are expired

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action