Buypass: Domain validation method using not allowed domain contact
Buypass reported an incident involving a TLS certificate issued using an incorrect domain validation method. The CA discovered that a validation specialist mistakenly used an email address from the DNS CAA iodef property instead of the allowed domain contact. The incident was identified on June 13, 2023, immediately after the certificate was issued, and the certificate was revoked the same day. Buypass has since ceased using external DNS tools for manual validations and has provided additional training to its validation specialists to prevent future occurrences. A new incident report was registered to address the situation comprehensively.
- Buypass discovered a misissuance incident involving an incorrect domain validation method.
- Buypass confirmed they would stop using external DNS tools for validations.
- Buypass registered a new bug with a detailed incident report.
- Buypass — Buypass reported an incident involving a TLS certificate issued based on an illegal domain contact.
- Mm representative — Questions were raised regarding the manual validation process and the use of external DNS tools.
- Buypass — Buypass confirmed they would stop using external DNS tools for manual validations.
- Buypass — Buypass registered a new bug with a new incident report.