SSL.com: CAA Empty set handling results in Wildcard issuance
SSL.com reported a compliance issue regarding the issuance of a wildcard TLS certificate due to a misinterpretation of CAA records. The incident was triggered by a Certificate Problem Report received on November 15, 2024, which indicated that the absence of an 'issuewild' property was incorrectly interpreted as permission to issue the wildcard certificate. Following an investigation, SSL.com acknowledged the violation of their own Certificate Policy and promptly revoked the certificate. They implemented a patch to prevent future occurrences and updated their testing procedures to include this edge case. The final incident report was submitted on December 4, 2024, and all action items have been completed.
- SSL.com received a Certificate Problem Report regarding a potential mis-processing of CAA records.
- The wildcard certificate was revoked.
- SSL.com submitted the Final Incident Report.
- SSL.com — SSL.com submitted a Preliminary Incident Report regarding the CAA issue.
- SSL.com — SSL.com submitted the Final Incident Report detailing the incident and remediation steps.
- Mozilla representative — Mozilla requested SSL.com to update the incident report for more detail.
- SSL.com — SSL.com provided an Incident Report Closure Summary.