← DigiCert cases
Bugzilla #1914911 Certificate Misissuance

DigiCert: Unclear Disclosure of CAA Issuer Domain Names

CLOSED DigiCert
AI Summary

DigiCert faced an issue regarding unclear language in their Certificate Policy/Certification Practice Statement (CP/CPS) about CAA Issuer Domain Names. An external report highlighted that the CPS suggested the use of domains like 'digicert.XX', which was not implemented in their systems. This led to the discovery that 'symantec.com' was inadvertently removed from the list of approved CAA domains, resulting in the misissuance of 185 certificates. DigiCert has since revoked these certificates and updated their CPS to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 11:45 UTC Confidence: 0.95
Chronology
  1. Bug reported by external researcher.
  2. 185 misissued certificates identified and revocation initiated.
  3. All affected certificates revoked.
  4. Automated comparison system for CPS and CAA implementation deployed.
  5. Case closed after completion of all action items.
Participants
Tim Hollebeek Andrew Ayer
External References
Similar Local Cases
#1936906 RESOLVED Certificate Misissuance Opened 2024-12-12 · Closed 2025-02-14 · 56% similar
DigiCert: Invalid Characters in S/MIME Subject Fields
#1353827 RESOLVED Certificate Misissuance Opened 2017-04-05 · Closed 2023-02-22 · 54% similar
DigiCert: DigiCert issued cert with CN too long
#1531817 RESOLVED Certificate Misissuance Opened 2019-03-01 · Closed 2023-02-22 · 53% similar
DigiCert: in-addr.arpa Misissuance
#1684442 RESOLVED Certificate Misissuance Opened 2020-12-29 · Closed 2023-02-22 · 52% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01
#1500621 RESOLVED Certificate Misissuance Opened 2018-10-19 · Closed 2023-02-22 · 52% similar
DigiCert: Internal Domain Name cert mis-issuance
#1409735 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2024-05-09 · 52% similar
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
#1397960 RESOLVED Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 52% similar
DigiCert / Telecom Italia: Several Problems
#1888016 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2024-06-05 · 51% similar
Digicert: Failure to include CPS URI in 1 certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action