← DigiCert cases
Bugzilla #2017185 Certificate Misissuance

DigiCert: CAA processing during network disruption

RESOLVED DigiCert
AI Summary

DigiCert experienced a network disruption on February 12, 2026, which led to the issuance of certificates without proper CAA verification. The CAA Service incorrectly treated internal timeouts as external DNS lookup failures, resulting in 41,105 certificates being affected. All affected certificates were revoked within the required timeframes, and DigiCert has since implemented measures to ensure compliance with TLS BR requirements.

Model: gpt-4o-mini Generated: 2026-06-13 11:48 UTC Confidence: 0.95
Chronology
  1. MPIC Service experiences intermittent disruption
  2. Third party reports potential mis-issuance
  3. Initial certificate revoked
  4. All remaining valid certificates revoked
  5. Incident report closure summary provided
Participants
DigiCert CCADB Incident Reporting
External References
Similar Local Cases
#2033170 ASSIGNED Certificate Misissuance Opened 2026-04-18 Still Open · 57% similar
DigiCert: Misissued code signing certificates
#2032485 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 55% similar
DigiCert: Misissuance detected by PKIMetal
#1888016 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2024-06-05 · 52% similar
Digicert: Failure to include CPS URI in 1 certificate
#1397954 RESOLVED Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 52% similar
DigiCert / Siemens: Insufficient Serial Number Entropy
#1335132 RESOLVED Certificate Misissuance Opened 2017-01-30 · Closed 2023-02-22 · 52% similar
DigiCert: Verizon mis-issued test certificates
#1684442 RESOLVED Certificate Misissuance Opened 2020-12-29 · Closed 2023-02-22 · 51% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01
#1401407 RESOLVED Certificate Misissuance Opened 2017-09-19 · Closed 2023-02-22 · 51% similar
DigiCert: Mis-Issuance Rekey certificates
#1914911 RESOLVED Certificate Misissuance Opened 2024-08-26 · Closed 2025-01-08 · 50% similar
DigiCert: Unclear Disclosure of CAA Issuer Domain Names

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action