← Apple Inc. cases
Bugzilla #1841534 Self Reported Incident Certificate Misissuance

Apple: TLS certificates issued outside the TTL of the CAA record

RESOLVED FIXED Apple Inc.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Apple reported a compliance issue it discovered during its annual CCADB Self Assessment. Apple found that, in some cases requiring additional issuance approvals, BRs 3.2.2.8 were not met because more than 8 hours passed between the CAA lookup and certificate issuance, even though the CAA record TTL for affected certificates was less than 8 hours. Apple stated that its initial investigation indicated 1,726 valid impacted certificates issued to domains Apple owns. Apple deployed a software fix on June 30, 2023 to ensure the CAA check is performed immediately before issuance, and it updated pre-issuance controls on July 3, 2023. Apple also communicated to affected teams that certificates would need to be replaced and revoked, and it filed the Bugzilla incident report. Apple later reported adding additional post-issuance monitoring and stated there were no additional remediation items, considering the issue resolved unless further questions were raised. The bug was closed after Mozilla indicated it would close it on or about 23-Aug-2023 absent further concerns.

Model: gpt-5.4-nano Generated: 2026-06-13 15:14 UTC Revised: 2026-06-16 18:05 UTC Confidence: 0.90 9 comments
Chronology
  1. Apple discovered during its annual CCADB Self Assessment that some TLS certificates were issued after the CAA TTL/8-hour requirement was exceeded due to delays between CAA lookup and issuance.
  2. Apple deployed a production software fix to perform the CAA check immediately before certificate issuance.
  3. Apple updated pre-issuance controls and notified Apple teams with affected certificates to replace and revoke them.
  4. Apple reported adding post-issuance monitoring and stated the incident was resolved with no further remediation items.
Thread Activity
  1. Apple representative — Apple disclosed that on June 29, 2023 it discovered BR 3.2.2.8 violations where more than 8 hours passed between CAA lookup and issuance, and that it had deployed a fix on June 30 while continuing investigation.
  2. Apple representative — Apple provided attachments listing all affected certificates and valid affected certificates.
  3. Apple representative — Apple stated it added additional post-issuance monitoring and considered the issue resolved with no additional remediation items.
  4. Apple representative — Apple asked whether the incident could be closed, noting no outstanding tasks.
  5. Mozilla representative — Mozilla indicated it would close the bug on or about 23-Aug-2023 unless additional concerns or questions arose.
  6. Apple representative — Apple said it would continue to monitor the bug for comments and questions.
Participants
Apple representative Mozilla representative
Similar Local Cases
#1955365 RESOLVED Self Reported Incident Opened 2025-03-20 · Closed 2025-05-19 · 97% similar
Apple: Public Key Reuse
#1777757 RESOLVED Certificate Misissuance Opened 2022-07-02 · Closed 2023-02-22 · 96% similar
Apple: EV TLS pre-certificates issued without EKU extension
#1588001 RESOLVED Self Reported Incident Opened 2019-10-11 · Closed 2023-02-22 · 94% similar
Apple: OCSP responders return responses with incorrect issuer
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 82% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 81% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1894560 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 81% similar
DigiCert: Incorrect case in Business Category
#1876565 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-01-25 · Closed 2024-04-06 · 81% similar
Izenpe: Not allowed Qualifier ID OID on Certificate Policies extension
#1746945 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-12-20 · Closed 2023-02-22 · 81% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action