SSL.com: Entrust API and CAA checking
This case involves a report of a misissued wildcard certificate for the domain *.hyatt-test.com, which was issued by SSL.com despite a CAA record that should have prevented such issuance. The issue was triggered by a user who created a CAA record indicating no certificates should be issued for the domain. SSL.com acknowledged the report and initiated an investigation to determine if the issuance violated CAA policies. The investigation revealed ambiguity in the interpretation of RFC 8659 regarding the handling of CAA records, particularly concerning wildcard certificates. The case has been marked as a duplicate of another bug (1932973) that encompasses the underlying issues.
- A wildcard certificate for *.hyatt-test.com was issued when it should not have been.
- The bug was marked as a duplicate of Bug 1932973.
- Community commenter — Reported the misissuance of a wildcard certificate despite a CAA record.
- SSL.com — Acknowledged the report and confirmed an investigation was initiated.
- Mozilla representative — Closed this bug as a duplicate of Bug 1932973.