Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
Mark Penny (Citi) reported that Google Trust Services (GTS) issued two certificates for bt-preview.citicards.citi.com even though a CAA record existed for the citi.com domain, and he cited CABF Baseline Requirements and GTS’s Certificate Policy CAA record checking requirements. Citi stated the two certificates were revoked at Citi’s request and asked what went wrong. GTS investigated and said its audit logs showed the CAA record for the leaf domain bt-preview.citicards.citi.com included pki.goog and another CA at the time of issuance. GTS also reported that a Google Cloud managed service that requested the certificates indicated it does not control customer DNS, suggesting the DNS change was made by someone with control of Citi’s DNS. GTS checked its RFC 8659 logic and said it was correct and that the correct resource records were used. GTS concluded there was no evidence of a problem with issuance validations and asked that the bug be closed as invalid; Mozilla indicated it would close it as Invalid unless contradicted. Mark Penny agreed to close the matter as planned.
- Citi reported that GTS had issued certificates despite an existing CAA record and requested feedback on the CAA checking failure.
- GTS reported its investigation findings, including that the CAA record for the leaf domain was in place at issuance and that its implementation of RFC 8659 logic was correct.
- GTS requested closure as invalid due to no evidence of a validation problem.
- Citi confirmed it considered the matter closed and asked Mozilla to close the bug as planned.
- Citi representative — Reported two GTS-issued certificates for bt-preview.citicards.citi.com despite an existing CAA record for citi.com, noted the certificates were revoked at Citi’s request, and asked what went wrong with CAA record checking.
- Google representative — Acknowledged receipt and said GTS was looking into the issue.
- Google representative — Provided an initial update that audit logs showed the CAA record for the leaf domain included pki.goog and another CA at issuance, and said GTS was continuing investigation.
- Google representative — Concluded investigation, stated evidence showed the CAA record was in place for the leaf domain at issuance, cited contact with the Google Cloud managed service about DNS control, and said RFC 8659 logic was implemented correctly; asked to close as invalid unless a formal incident report was desired.
- Google representative — Said GTS was monitoring and believed the bug should be closed as invalid due to no evidence of a validation problem.
- Mozilla representative — Indicated Mozilla would close the bug as Invalid on or about 25-Jan-2023 unless contradicted.
- Citi representative — Thanked GTS for the analysis and asked Ben to close as planned.