SSL.com: Failure to process CAA records from one SubCA
SSL.com identified a compliance issue related to the failure to process CAA records for a CA certificate, affecting 57 TLS certificates, 7 of which were still active. This issue was discovered during a retroactive verification of post-ceremony actions as part of a previous bug. SSL.com remediated the issue by revoking the active certificates within 24 hours of discovery and submitted a preliminary incident report. A final incident report detailed the root cause, which included misconfiguration and peer review failures. SSL.com has since updated its documentation and processes to prevent future occurrences, and all action items have been completed.
- SSL.com submitted a preliminary incident report after discovering a CAA configuration issue.
- SSL.com submitted a final incident report detailing the root cause and remediation steps.
- Mozilla plans to close the bug unless further issues arise.
- SSL.com — SSL.com identified a CA certificate without proper CAA validation and reported 57 affected TLS certificates.
- SSL.com — Final incident report submitted, detailing the root cause and remediation actions.
- SSL.com — Incident report closure summary provided, confirming completion of all action items.
- Mozilla representative — Mozilla indicated plans to close the bug unless further issues arise.