← Google Trust Services LLC cases
Bugzilla #1809864
Certificate Misissuance
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
RESOLVED
INVALID
Google Trust Services LLC
AI Summary
Google Trust Services LLC issued two certificates for the subdomain bt-preview.citicards.citi.com despite an existing CAA record that should have prevented this. The certificates were revoked at the request of Citi. An investigation revealed that the CAA record was in place at the time of issuance, suggesting a potential misconfiguration by someone with control over the DNS settings. Google Trust Services concluded that their issuance process was compliant with the relevant standards and closed the case as invalid.
Chronology
- Initial report of mis-issued certificates
- Google Trust Services concluded investigation
- Google Trust Services proposed to close the case as invalid
- Citi confirmed closure of the matter
Participants
Mark Penny
James Longmore
External References
Similar Local Cases
Google Trust Services: 63 bit serial numbers in some certificates
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
GlobalSign: 4 Misissued certificates with invalid CN
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record