DigiCert: Unclear Disclosure of CAA Issuer Domain Names
DigiCert opened this case following a report regarding unclear language in their Certificate Policy/Certification Practice Statement (CP/CPS) related to CAA Issuer Domain Names. An investigation revealed that the language suggested the use of domains of the form 'digicert.XX', which was not implemented in their systems. Additionally, it was found that 'symantec.com' had been inadvertently omitted from the list of approved CAA domains, leading to the issuance of 185 misissued certificates. DigiCert revoked these certificates within the required timeframe and updated their CPS to correct the omissions. They have also implemented additional technical reviews and automated checks to prevent similar issues in the future.
- DigiCert receives a report about unclear CAA Issuer Domain Names in their CPS.
- All misissued certificates relying on the omitted CAA domain are revoked.
- DigiCert posts a closing summary detailing the incident and remediation steps.
- Mm representative — Reported unclear language in DigiCert's CPS regarding CAA Issuer Domain Names.
- DigiCert — Confirmed that 185 certificates were misissued due to the omission of 'symantec.com' from the CPS.
- DigiCert — Posted a closing summary detailing the incident and remediation actions.