← Google Trust Services LLC cases
Bugzilla #1902670 Certificate Misissuance Revocation Issue

Google Trust Services: SXG certificates issued without correctly checking CAA restrictions

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) disclosed an incident involving the issuance of SXG certificates. GTS identified a corner case introduced during refactoring where SXG issuance did not correctly check additional CAA requirements specified in its CP for SXG certificates. Specifically, GTS required the presence of an "issue" or "issuewild" CAA property to authorize issuance, but it did not properly handle cases where no applicable "issue"/"issuewild" records were present while other CAA records were present (e.g., only an "iodef" property, or a non-wildcard FQDN with only an "issuewild" property). During incident handling, GTS deployed a fix, stopped SXG issuance for about 2 hours and 28 minutes, and revoked all affected active certificates within 24 hours of discovery. GTS reported that 58 SXG certificates were issued due to the CAA bug from July 19, 2022 to June 14, 2024, with 12 certificates (9 active at discovery plus 3 additional misissued during handling) revoked within 24 hours. GTS also listed and completed a set of action items (including adding SXG deny tests to caatestsuite.com) and requested the bug be closed; Mozilla indicated it would close it around July 31, 2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 9 comments
Chronology
  1. First SXG certificate affected by the CAA-checking bug was issued.
  2. GTS discovered a potential CAA bug affecting SXG certificates and began remediation steps.
  3. First unsuccessful rollout attempt to fix the issue was started.
  4. GTS confirmed the CAA bug affecting SXG certificates and reported the incident.
  5. GTS proposed a PR to add SXG deny tests to caatestsuite.com, completing the last remaining action item.
  6. GTS stated all action items were complete and requested closure.
Thread Activity
  1. Google representative — GTS reported it was investigating SXG certificate issuance without correctly verifying CAA record parameters, said a fix was deployed, and stated affected certificates would be revoked within 24 hours.
  2. Google representative — GTS posted a full incident report describing the SXG-specific CAA corner case, the impact (58 issued; 12 revoked), and the remediation and timeline, including that TLS CAA checks were unaffected.
  3. Mm representative — A commenter asked for examples clarifying how the "cansignhttpexchanges" requirement was and was not enforced, and suggested adding SXG checks to caatestsuite.com.
  4. Google representative — GTS provided a table of CAA record sets showing expected TLS vs SXG outcomes and the faulty-code outcomes, and discussed practices for handling draft requirements.
  5. Google representative — GTS said it was monitoring the bug and listed remaining action items with due dates, requesting the NextUpdate field be set to July 12.
  6. Google representative — GTS reported completing formal analysis of RFC 8659, RFC 8657, and the SXG draft specification and said identified tests/code changes were made and would reach production in the next rollout.
  7. Google representative — GTS reported it proposed a PR to add SXG deny tests to caatestsuite.com, completing the last remaining action item.
  8. Google representative — GTS stated all action items were complete and requested the bug be closed if no further comments or questions.
  9. Mozilla representative — Mozilla said it would close the bug on or about July 31, 2024 unless additional comments or questions were raised.
Participants
Google representative Mm representative Mozilla representative
Similar Local Cases
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 89% similar
DigiCert: Random value in CNAME without underscore prefix
#1876593 RESOLVED Validation Issue Revocation Issue Opened 2024-01-25 · Closed 2024-06-06 · 87% similar
Google Trust Services: Failure to properly validate IP address
#1709223 RESOLVED Certificate Misissuance Opened 2021-05-03 · Closed 2023-02-22 · 85% similar
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage
#1894054 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-04-29 · Closed 2024-07-03 · 78% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 78% similar
Sectigo: test certificates issued from trusted CA
#1914020 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-08-20 · Closed 2024-09-13 · 77% similar
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 77% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1896596 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-14 · Closed 2024-07-24 · 77% similar
SECOM: Certificates Issued with lower case value in subject:countryName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action