Apple: TLS certificates issued outside the TTL of the CAA record
Apple reported a compliance issue it discovered during its annual CCADB Self Assessment. Apple found that, in some cases requiring additional issuance approvals, BRs 3.2.2.8 were not met because more than 8 hours passed between the CAA lookup and certificate issuance, even though the CAA record TTL for affected certificates was less than 8 hours. Apple stated that its initial investigation indicated 1,726 valid impacted certificates issued to domains Apple owns. Apple deployed a software fix on June 30, 2023 to ensure the CAA check is performed immediately before issuance, and it updated pre-issuance controls on July 3, 2023. Apple also communicated to affected teams that certificates would need to be replaced and revoked, and it filed the Bugzilla incident report. Apple later reported adding additional post-issuance monitoring and stated there were no additional remediation items, considering the issue resolved unless further questions were raised. The bug was closed after Mozilla indicated it would close it on or about 23-Aug-2023 absent further concerns.
- Apple discovered during its annual CCADB Self Assessment that some TLS certificates were issued after the CAA TTL/8-hour requirement was exceeded due to delays between CAA lookup and issuance.
- Apple deployed a production software fix to perform the CAA check immediately before certificate issuance.
- Apple updated pre-issuance controls and notified Apple teams with affected certificates to replace and revoke them.
- Apple reported adding post-issuance monitoring and stated the incident was resolved with no further remediation items.
- Apple representative — Apple disclosed that on June 29, 2023 it discovered BR 3.2.2.8 violations where more than 8 hours passed between CAA lookup and issuance, and that it had deployed a fix on June 30 while continuing investigation.
- Apple representative — Apple provided attachments listing all affected certificates and valid affected certificates.
- Apple representative — Apple stated it added additional post-issuance monitoring and considered the issue resolved with no additional remediation items.
- Apple representative — Apple asked whether the incident could be closed, noting no outstanding tasks.
- Mozilla representative — Mozilla indicated it would close the bug on or about 23-Aug-2023 unless additional concerns or questions arose.
- Apple representative — Apple said it would continue to monitor the bug for comments and questions.