DigiCert domain validation bug involving CNAME records without an underscore prefix
DigiCert reported a domain validation bug in its OEM validation system where a random value used in a CNAME record was not prefixed with an underscore as required by the Baseline Requirements. DigiCert said the issue could allow mis-issuance, identified 83,267 affected TLS certificates, and later reported 1,308 affected S/MIME certificates as well. The company said it began revoking impacted certificates, attached lists of affected serial numbers, and later stated that all 83,267 certificates and all affected S/MIME certificates had been revoked. DigiCert also said it fixed the technical bug, completed the listed remediation items, and released an open source validation system for community review. The bug was eventually marked ready for closure, and Mozilla indicated it would be closed after the closure summary was posted.
- DigiCert discovered a CNAME validation path that could issue certificates without an underscore-prefixed random value.
- DigiCert identified 83,267 affected certificates and said revocation would begin within the 24-hour window.
- DigiCert reported that 83,267 affected certificates had been revoked and that 1,308 affected S/MIME certificates were also being revoked.
- DigiCert announced the initial release of its open source validation project and said the proposed remediations were complete.
- DigiCert posted a closure summary stating all action items were completed.
- DigiCert — DigiCert said it had received a certificate problem report, found a potential mis-issuance path in DNS-based validation, and was investigating impacted certificates.
- Google representative — Google said the Chrome Root Program cannot grant exceptions to CA/Browser Forum revocation requirements and would evaluate the incident case by case.
- DigiCert — DigiCert said it had identified 83,267 impacted certificates across 6,807 subscribers and planned to begin revoking within the 24-hour window.
- DigiCert — DigiCert posted a detailed incident report describing the root cause, impact, and remediation plan.
- DigiCert — DigiCert said it had completed revocation of the 83,267 affected certificates and had found 1,308 affected S/MIME certificates.
- DigiCert — DigiCert confirmed the technical bug had been fixed and said it would provide more details about preventing recurrences.
- DigiCert — DigiCert said it would deprecate validation methods not part of its open source DCV project and transition customers to more automatable methods.
- DigiCert — DigiCert announced the initial release of its open source validation project and said all proposed remediations were complete.
- DigiCert — DigiCert posted a closure summary stating that all listed action items were completed.
- Mozilla representative — Mozilla asked DigiCert to file a closure summary and then said the bug would be slated for closure.