← Buypass cases
Bugzilla #1872371 Certificate Problem Report

Buypass: Using an external DNS Resolver for DNS lookups

RESOLVED FIXED Buypass
AI Summary

Buypass issued TLS certificates using external DNS resolvers for domain validation, which is not compliant with the Baseline Requirements as it constitutes a Delegated Third Party (DTP). This affected approximately 177,060 active certificates. Upon discovering the issue, Buypass ceased certificate issuance, switched to internal DNS resolvers, and began notifying affected subscribers. The root cause was a misunderstanding of the DTP requirements, leading to the use of external DNS resolvers since 2017. Buypass has since engaged with the CA/Browser Forum to clarify these requirements and updated internal policies to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Confidence: 0.90
Chronology
  1. Buypass ACME in production using internal DNS resolvers.
  2. Buypass became aware that using external DNS resolvers is considered a DTP.
  3. Buypass notified subscribers and resumed certificate issuance using internal DNS resolvers.
Participants
Mads Henriksveen
External References
Similar Local Cases
#1839305 RESOLVED Certificate Problem Report Opened 2023-06-20 · Closed 2024-06-30 · 66% similar
Buypass: Domain validation method using externally operated DNS tools
#1838421 RESOLVED Certificate Problem Report Opened 2023-06-14 · Closed 2024-06-30 · 60% similar
Buypass: Domain validation method using not allowed domain contact
#1539307 RESOLVED Certificate Problem Report Opened 2019-03-27 · Closed 2023-02-22 · 59% similar
Buypass: Insufficient Serial Number Entropy
#1632632 RESOLVED Certificate Problem Report Opened 2020-04-23 · Closed 2023-02-22 · 59% similar
Buypass: Illegal Business Category in a PSD2 QWAC
#1654216 RESOLVED Certificate Problem Report Opened 2020-07-21 · Closed 2023-02-22 · 59% similar
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
#1864204 RESOLVED Certificate Problem Report Opened 2023-11-10 · Closed 2024-05-10 · 58% similar
Buypass: TLS certificates with incorrect Subject attribute order
#1626078 RESOLVED Certificate Problem Report Opened 2020-03-30 · Closed 2023-02-22 · 57% similar
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
#1628292 RESOLVED Certificate Problem Report Opened 2020-04-08 · Closed 2023-02-22 · 57% similar
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action