← Google Trust Services LLC cases
Bugzilla #1902670
Certificate Problem Report
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
RESOLVED
FIXED
Google Trust Services LLC
AI Summary
Google Trust Services identified an issue where SXG certificates were issued without properly verifying CAA record parameters, violating their Certificate Policy. A total of 58 certificates were affected, with 12 being active at the time of discovery. All affected certificates were revoked within 24 hours. The issue arose from a bug in the code that failed to enforce additional CAA checks required for SXG certificates. Google Trust Services has since deployed a fix and is monitoring the situation.
Chronology
- Issue with SXG certificate issuance discovered.
- Incident report published detailing the bug and its impact.
- Proposed tests for SXG certificates added to caatestsuite.com.
- All action items related to the incident completed.
Participants
gts-external@google.com
agwa-bugs@mm.beanwood.com
bwilson@mozilla.com
External References
Similar Local Cases
Google Trust Services: Failure to send preliminary report to subscriber within 24h
Google Trust Services: Inconsistent MPCAA secondary perspective logging
Telia: Invalid email contact address was used for few domains
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
SSL.com: CAA Empty set handling results in Wildcard issuance
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
Google Trust Services: Incorrect OCSP responses for certain certificates
Google Trust Services: incorrect SCT in certificate