← Buypass cases
Bugzilla #1839305 Ca Certificate Compliance

Buypass incident report: externally operated DNS tools used for domain validation

RESOLVED FIXED Buypass
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Buypass reported an incident involving TLS certificates issued after manual domain validation used externally operated DNS tools. Buypass said it learned of the problem on 2023-06-16 after reading a comment in Bugzilla, then stopped using the externally operated DNS tools the same day. The initial report identified six still-valid affected certificates, plus one certificate from the original bug, and said the last revoked certificate was revoked on 2023-06-17. Mozilla and other commenters asked for a more specific remediation plan and clarification of the DNS tooling and validation process. Buypass later said it would switch to an internal DNS resolver, filed a new incident report in bug 1872371, and stated on 2024-03-15 that there were no remaining action items in this bug. The bug was resolved FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:18 UTC Confidence: 0.96 31 comments
Chronology
  1. Buypass stopped using externally operated DNS tools for manual domain validation.
  2. The last affected certificate identified in the incident was revoked.
  3. Buypass said it had stopped issuing certificates using an external DNS resolver and was switching to an internal DNS resolver.
  4. Buypass registered a new incident report in bug 1872371.
  5. Buypass said there were no remaining action items in this bug.
Thread Activity
  1. Buypass — Buypass opened the incident report and described the use of externally operated DNS tools for manual domain validation, the affected certificates, and the revocation timeline.
  2. Google representative — Mozilla requested a revised resolution plan with more actionable detail and completion dates.
  3. Buypass — Buypass said it had stopped using externally operated DNS tools and described planned internal reorganization and automation work.
  4. Google representative — Mozilla asked for more specificity on the status and completion date of each remediation step.
  5. Buypass — Buypass provided dates for defining changes to automation and completing automation for methods 2, 4, and 7.
  6. Buypass — Buypass said it had made decisions on internal reorganization and had specified changes for automation work.
  7. Buypass — Buypass said more resources had been added and the automation changes were in test, with production deployment planned by 2024-01-12.
  8. Buypass — Buypass said the automation changes were deployed into production.
  9. Buypass — Buypass said it was using in-house software for DNS lookups based on dnsjava.
  10. Buypass — Buypass acknowledged that using an externally operated DNS tool for manual domain validation must be considered a Delegated Third Party and said it would raise the issue in the CA/Browser Forum.
  11. Buypass — Buypass said it had stopped issuing certificates using an external DNS resolver and would post a new incident report by 2023-12-29.
  12. Buypass — Buypass said it had registered a new bug for the new incident report, bug 1872371.
  13. Mozilla representative — Mozilla asked whether any remaining action items existed or whether the bug should be closed.
  14. Buypass — Buypass said there were no remaining action items and suggested closing the bug.
Participants
Buypass Google representative Community commenter Daknob representative Mm representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1838421 RESOLVED Ca Certificate Compliance Opened 2023-06-14 · Closed 2024-06-30 · 99% similar
Buypass: Domain validation method using not allowed domain contact
#1864204 RESOLVED Ca Certificate Compliance Opened 2023-11-10 · Closed 2024-05-10 · 96% similar
Buypass: TLS certificates with incorrect Subject attribute order
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 78% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1705187 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-14 · Closed 2023-02-22 · 77% similar
KIR S.A.: CN domain not in SAN
#1871113 RESOLVED Ca Certificate Compliance Opened 2023-12-20 · Closed 2024-05-15 · 76% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1734917 RESOLVED Ca Certificate Compliance Opened 2021-10-08 · Closed 2023-02-22 · 76% similar
IdenTrust: Mis-Issued EV Certificates
#1886406 RESOLVED Ca Certificate Compliance Opened 2024-03-20 · Closed 2024-08-28 · 76% similar
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 76% similar
Certigna: TLS certificates with Basic constraint non-critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action