Buypass incident report: external DNS resolvers used for domain validation
Buypass reported that its ACME TLS certificate issuance had used external DNS resolvers for DNS lookups, which it said could be considered use of a Delegated Third Party and therefore not allowed for domain validation under the Baseline Requirements. Buypass stated that this affected 177,060 active TLS certificates and that about 20% were issued using dns-01, while the rest were issued using http-01 but still depended on DNS CAA lookups through the same external resolver. The company said it stopped issuing certificates on 2023-12-22, switched ACME to an internal DNS resolver the same day, and then resumed issuance. Buypass also said it identified affected certificates and subscribers, notified subscribers starting on 2023-12-28, and continued notifications afterward. Later comments noted that some pre-certificates had not been submitted to CT and were then submitted, and that Buypass was unable to revoke affected certificates within 5 days, with a separate bug opened for that revocation issue. Buypass said it updated internal policies and processes, engaged in the CABF Server Certificate Working Group to clarify DTP requirements, and by June 2024 reported that all action items were closed.
- Buypass ACME switched from internal to external DNS resolvers for DNS lookups.
- Buypass stopped issuing certificates, switched ACME back to an internal DNS resolver, and resumed issuance.
- Buypass began notifying affected subscribers to renew their certificates.
- Buypass said previously unsubmitted pre-certificates had been submitted to CT.
- Buypass reported updates to its DTP-related policies and processes.
- Buypass said all action items were closed.
- Buypass — Buypass opened the incident report describing external DNS resolver use for TLS domain validation and listed impact, timeline, root cause, and action items.
- Vittgam representative — A commenter noted that subscriber notification emails had been sent through Microsoft Corporation's Outlook/Office365 servers.
- Community commenter — A commenter said Microsoft email delivery was not an issue unless it was directly used in domain validation, and asked Buypass to explain the root cause and commit to monitoring related incident reports.
- Buypass — Buypass said it was unable to revoke affected certificates within 5 days and pointed to a separate bug for that revocation issue.
- Community commenter — A commenter said the expected revocation timeframe for this class of incident was 24 hours.
- Buypass — Buypass said the listed pre-certificates had not been submitted to CT and had now been submitted.
- Buypass — Buypass explained that it now understood both externally operated web services and recursive DNS resolvers as DTP-related issues and said the BR should be clarified.
- Buypass — Buypass reported that it was engaging with the CABF SCWG and had updated internal policies and processes.
- Buypass — Buypass said there was no new information and that all action items had been closed.
- Mozilla representative — Mozilla said it would close the bug on or about 2024-07-19.