← Buypass cases
Bugzilla #1838421 Ca Certificate Compliance

Buypass: Domain validation method using not allowed domain contact

RESOLVED FIXED Buypass
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Buypass reported an incident involving a TLS certificate issued using an incorrect domain validation method. The CA discovered that a validation specialist mistakenly used an email address from the DNS CAA iodef property instead of the allowed domain contact. The incident was identified on June 13, 2023, immediately after the certificate was issued, and the certificate was revoked the same day. Buypass has since ceased using external DNS tools for manual validations and has provided additional training to its validation specialists to prevent future occurrences. A new incident report was registered to address the situation comprehensively.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:18 UTC Confidence: 0.85 29 comments
Chronology
  1. Buypass discovered a misissuance incident involving an incorrect domain validation method.
  2. Buypass confirmed they would stop using external DNS tools for validations.
  3. Buypass registered a new bug with a detailed incident report.
Thread Activity
  1. Buypass — Buypass reported an incident involving a TLS certificate issued based on an illegal domain contact.
  2. Mm representative — Questions were raised regarding the manual validation process and the use of external DNS tools.
  3. Buypass — Buypass confirmed they would stop using external DNS tools for manual validations.
  4. Buypass — Buypass registered a new bug with a new incident report.
Participants
Buypass Mm representative
External References
Similar Local Cases
#1839305 RESOLVED Ca Certificate Compliance Opened 2023-06-20 · Closed 2024-06-30 · 99% similar
Buypass: Domain validation method using externally operated DNS tools
#1864204 RESOLVED Ca Certificate Compliance Opened 2023-11-10 · Closed 2024-05-10 · 90% similar
Buypass: TLS certificates with incorrect Subject attribute order
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 70% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 69% similar
Camerfirma: suspicious certificate for com.com
#1716163 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 69% similar
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 68% similar
IdenTrust: Mis-Issued EV Certificates
#1672423 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 67% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 67% similar
GoDaddy: Certificates with invalid embedded SCT signatures

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action