DigiCert: CAA processing during network disruption
On February 12, 2026, DigiCert experienced a disruption in its MPIC Service, leading to the issuance of certificates without proper CAA verification due to internal timeouts being misinterpreted as external failures. This incident was reported by a third party on February 13, prompting DigiCert to investigate and identify 41,105 affected certificates, all of which were subsequently revoked. DigiCert implemented a fix to enforce fail-closed behavior during such disruptions and completed several action items to enhance monitoring and compliance. The incident was resolved, and a final report was submitted on April 7, 2026.
- MPIC Service experiences disruption, leading to mis-issued certificates.
- Third party reports potential mis-issuance to DigiCert.
- Initial certificate revoked within 24 hours of notification.
- DigiCert submits final incident report and requests closure.
- DigiCert — Preliminary incident report submitted detailing the CAA processing issue.
- DigiCert — Full incident report provided with timeline and remediation actions.
- DigiCert — Action items related to the incident have been completed.
- DigiCert — Final report closure summary submitted.