← Apple Inc. cases
Bugzilla #1841534
Certificate Problem Report
Apple: TLS certificates issued outside the TTL of the CAA record
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple Inc. identified an issue where TLS certificates were issued beyond the allowed time frame specified by the CAA record, affecting 1,726 valid certificates. The problem arose when additional issuance approvals delayed the process, resulting in certificate issuance occurring more than 8 hours after the CAA lookup. A fix was deployed on June 30, 2023, and post-issuance monitoring was added to ensure compliance. The issue has been resolved, and no further actions are pending.
Chronology
- Issue discovered during CCADB Self Assessment
- Fix deployed to ensure CAA check is performed before issuance
- Initial issue report filed
- Post-issuance monitoring added
- No outstanding tasks reported
- Monitoring for comments and questions continued
Participants
certification_authority@apple.com
bwilson@mozilla.com
External References
Similar Local Cases
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple: EV Certificate Approver Authorization
Apple: Public Key Reuse
Apple: Test website certificates expired
Apple: CRLs for dormant CAs will not be populated in CCADB
Apple: OCSP availability 2020-11-12
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
Apple: OCSP responders return responses with incorrect issuer