← Internet Security Research Group cases
Bugzilla #1398427 · Certificate Misissuance

Let's Encrypt: CAA Misissuances

Internet Security Research Group · RESOLVED
AI Summary

This case addresses misissuances by Let's Encrypt related to CAA checking requirements. Two certificates were issued in violation of the Baseline Requirements, prompting an investigation and subsequent revocation of the certificates. Let's Encrypt acknowledged the compliance issues and implemented changes to their CAA checking algorithm to align with the requirements. The matter was resolved with a commitment to ongoing compliance.

Model: gpt-4o-mini Generated: 2026-06-13 11:59 UTC Confidence: 0.95
Chronology
  1. Initial report of CAA misissuances
  2. Certificates revoked and fixes deployed
  3. CAA checking algorithm updated for compliance
  4. Mozilla confirmed no misissuance for cert #1
Participants
Josh Aas Andrew Ayer Kathleen Wilson Gervase Markham
Similar Local Cases
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 66% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 63% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 57% similar
SHA-1 issuance by Visa root
#1313873 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DocuSign root
#1313872 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DigiCert roots
#1397969 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 55% similar
DigiCert / Inteso San Paulo: Double dot characters
#1293366 RESOLVED Certificate Misissuance Opened 2016-08-08 · Closed 2022-11-14 · 52% similar
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
#1283498 RESOLVED Certificate Misissuance Opened 2016-06-30 · Closed 2022-11-14 · 52% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action