← Buypass cases
Bugzilla #1839305 Certificate Problem Report

Buypass: Domain validation method using externally operated DNS tools

RESOLVED FIXED Buypass
AI Summary

Buypass reported an incident involving the use of externally operated DNS tools for domain validation, which is not compliant with the Baseline Requirements as it constitutes the use of a Delegated Third Party (DTP). The issue was identified on June 16, 2023, and Buypass promptly ceased using these tools, revoking six affected certificates. They are now transitioning to an internal DNS resolver to ensure compliance. A revised resolution plan has been requested to detail the actions taken and their statuses, with a commitment to improve internal processes and automation to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.90
Chronology
  1. Buypass became aware of the problem and stopped using externally operated DNS tools.
  2. The last affected certificate was revoked.
  3. Buypass acknowledged the use of an external DNS resolver as a DTP and stopped issuing certificates using it.
  4. A new bug was registered with a new incident report.
Participants
Mads Henriksveen cclements@google.com amir@aaomidi.com daknob@daknob.net bwilson@mozilla.com
External References
Similar Local Cases
#1872371 RESOLVED Certificate Problem Report Opened 2023-12-29 · Closed 2024-08-07 · 66% similar
Buypass: Using an external DNS Resolver for DNS lookups
#1838421 RESOLVED Certificate Problem Report Opened 2023-06-14 · Closed 2024-06-30 · 60% similar
Buypass: Domain validation method using not allowed domain contact
#1539307 RESOLVED Certificate Problem Report Opened 2019-03-27 · Closed 2023-02-22 · 59% similar
Buypass: Insufficient Serial Number Entropy
#1632632 RESOLVED Certificate Problem Report Opened 2020-04-23 · Closed 2023-02-22 · 59% similar
Buypass: Illegal Business Category in a PSD2 QWAC
#1654216 RESOLVED Certificate Problem Report Opened 2020-07-21 · Closed 2023-02-22 · 59% similar
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
#1595113 RESOLVED Certificate Problem Report Opened 2019-11-08 · Closed 2023-02-22 · 58% similar
Buypass: Intermediate certificates not listed in audit reports
#1626078 RESOLVED Certificate Problem Report Opened 2020-03-30 · Closed 2023-02-22 · 58% similar
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
#1628292 RESOLVED Certificate Problem Report Opened 2020-04-08 · Closed 2023-02-22 · 58% similar
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action