← Buypass cases
Bugzilla #1838421
Certificate Problem Report
Buypass: Domain validation method using not allowed domain contact
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported an incident involving the issuance of a TLS certificate based on an incorrect domain validation method. The validation specialist mistakenly used an email address from the CAA iodef property instead of the correct method. The issue was identified shortly after the certificate was issued on June 13, 2023, leading to its immediate revocation. Buypass has since ceased using external DNS tools for validations and has implemented additional training for their validation specialists to prevent recurrence.
Chronology
- Validation specialist selected wrong email address from DNS CAA
- Affected certificate issued
- Certificate revoked after discovering the mistake
- Buypass stopped using external DNS tools for validations
Participants
Mads Henriksveen
External References
Similar Local Cases
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Using an external DNS Resolver for DNS lookups
Buypass: Domain validation method using externally operated DNS tools
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: TLS certificates with incorrect Subject attribute order
Buypass: Insufficient Serial Number Entropy
Buypass: intermediate certificates not revoked within BR time period