← Google Trust Services LLC cases
Bugzilla #1809864 Certificate Misissuance

Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking

RESOLVED INVALID Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Mark Penny (Citi) reported that Google Trust Services (GTS) issued two certificates for bt-preview.citicards.citi.com even though a CAA record existed for the citi.com domain, and he cited CABF Baseline Requirements and GTS’s Certificate Policy CAA record checking requirements. Citi stated the two certificates were revoked at Citi’s request and asked what went wrong. GTS investigated and said its audit logs showed the CAA record for the leaf domain bt-preview.citicards.citi.com included pki.goog and another CA at the time of issuance. GTS also reported that a Google Cloud managed service that requested the certificates indicated it does not control customer DNS, suggesting the DNS change was made by someone with control of Citi’s DNS. GTS checked its RFC 8659 logic and said it was correct and that the correct resource records were used. GTS concluded there was no evidence of a problem with issuance validations and asked that the bug be closed as invalid; Mozilla indicated it would close it as Invalid unless contradicted. Mark Penny agreed to close the matter as planned.

Model: gpt-5.4-nano Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.90 8 comments
Chronology
  1. Citi reported that GTS had issued certificates despite an existing CAA record and requested feedback on the CAA checking failure.
  2. GTS reported its investigation findings, including that the CAA record for the leaf domain was in place at issuance and that its implementation of RFC 8659 logic was correct.
  3. GTS requested closure as invalid due to no evidence of a validation problem.
  4. Citi confirmed it considered the matter closed and asked Mozilla to close the bug as planned.
Thread Activity
  1. Citi representative — Reported two GTS-issued certificates for bt-preview.citicards.citi.com despite an existing CAA record for citi.com, noted the certificates were revoked at Citi’s request, and asked what went wrong with CAA record checking.
  2. Google representative — Acknowledged receipt and said GTS was looking into the issue.
  3. Google representative — Provided an initial update that audit logs showed the CAA record for the leaf domain included pki.goog and another CA at issuance, and said GTS was continuing investigation.
  4. Google representative — Concluded investigation, stated evidence showed the CAA record was in place for the leaf domain at issuance, cited contact with the Google Cloud managed service about DNS control, and said RFC 8659 logic was implemented correctly; asked to close as invalid unless a formal incident report was desired.
  5. Google representative — Said GTS was monitoring and believed the bug should be closed as invalid due to no evidence of a validation problem.
  6. Mozilla representative — Indicated Mozilla would close the bug as Invalid on or about 25-Jan-2023 unless contradicted.
  7. Citi representative — Thanked GTS for the analysis and asked Ben to close as planned.
Participants
Citi representative Google representative Mozilla representative
Similar Local Cases
#1904748 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 70% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 68% similar
Sectigo: Missing character in subject:organizationName attribute value
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 68% similar
Sectigo: potentially invalid organizational validation certificates
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 68% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 68% similar
HARICA: S/MIME certificate issuance without proper validation
#1853719 RESOLVED Certificate Misissuance Opened 2023-09-18 · Closed 2023-10-26 · 67% similar
Once Revoked Let's Encrypt Certificate Actively Signing Malware
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 67% similar
GlobalSign: CRL contains invalid signature algorithm
#1931615 RESOLVED Certificate Misissuance Opened 2024-11-15 · Closed 2024-12-03 · 67% similar
SSL.com: Entrust API and CAA checking

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action