GlobalSign: Certificate issued to FQDN with malformed CAA
GlobalSign reported that it issued a DV TLS certificate for unither.com containing a malformed, ABNF-incompliant CAA record "globalsign.com; digicert.com," which breaches RFC 8659. The issue was triggered by a certificate problem report received on 16/03/2022 09:45 UTC, which GlobalSign escalated to its Compliance team. GlobalSign confirmed the reported certificate required revocation on 16/03/2022 13:23 and responded to the reporter on 16/03/2022 14:08. In parallel, GlobalSign reviewed historically issued certificates and CAA validation logs and confirmed 28 additional domains were misconfigured with malformed CAA records; these were in the same single certificate, and GlobalSign initiated revocation and replacement. GlobalSign deployed system changes with a CAA logic fix to production on 17/03/2022 07:36 and revoked all affected certificates by 17/03/2022 07:36. The bug was marked RESOLVED with resolution FIXED, and GlobalSign stated that all remedial activities were completed unless further questions remained.
- GlobalSign issued a certificate against a malformed CAA record for unither.com.
- GlobalSign issued a second certificate against malformed CAA records for 28 other domains.
- GlobalSign deployed a CAA logic fix and revoked all affected certificates.
- GlobalSign nv-sa — GlobalSign stated it was investigating after being made aware it issued a DV TLS certificate to a FQDN with a malformed CAA record and would post a full incident report by March 21, 2022.
- GlobalSign nv-sa — GlobalSign described how it became aware via a certificate problem report, confirmed the need for revocation, identified additional affected domains, deployed a CAA logic fix, and revoked all affected certificates.
- GlobalSign nv-sa — GlobalSign said all remedial activities were completed and the issue could be closed unless there were further questions.
- Community commenter — A commenter asked for clarification about whether remediation addressed systemic causes versus only the specific symptom.
- GlobalSign nv-sa — GlobalSign clarified that the CAA verification logic changes remediate the specific issue, and it was also looking to expand capacity for broader RFC-focused code review without committing to a precise timeline.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 6-May-2022, unless additional issues or questions arose.