← DigiCert cases
Bugzilla #2017185
Certificate Misissuance
DigiCert: CAA processing during network disruption
RESOLVED
DigiCert
AI Summary
DigiCert experienced a network disruption on February 12, 2026, which led to the issuance of certificates without proper CAA verification. The CAA Service incorrectly treated internal timeouts as external DNS lookup failures, resulting in 41,105 certificates being affected. All affected certificates were revoked within the required timeframes, and DigiCert has since implemented measures to ensure compliance with TLS BR requirements.
Chronology
- MPIC Service experiences intermittent disruption
- Third party reports potential mis-issuance
- Initial certificate revoked
- All remaining valid certificates revoked
- Incident report closure summary provided
Participants
DigiCert
CCADB Incident Reporting
External References
Similar Local Cases
DigiCert: Misissued code signing certificates
DigiCert: Misissuance detected by PKIMetal
Digicert: Failure to include CPS URI in 1 certificate
DigiCert / Siemens: Insufficient Serial Number Entropy
DigiCert: Verizon mis-issued test certificates
DigiCert: SHA-1 intermediate issued after 2016-01-01
DigiCert: Mis-Issuance Rekey certificates
DigiCert: Unclear Disclosure of CAA Issuer Domain Names