← DigiCert cases
Bugzilla #1420861 · Certificate Problem Report
DigiCert / Thawte: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
DigiCert · RESOLVED
AI Summary
This case addresses a potential mis-issuance of a certificate by Thawte involving a mix of wildcard and non-wildcard DNS names in the Subject Alternative Name (SAN). The issue arose when it was suspected that CAA checks were bypassed during issuance. However, the CA provided logs indicating that no CAA records were found, suggesting that the issuance was valid. The discussion highlights the challenges in verifying CAA compliance and the need for improved transparency in the process.
Chronology
- Bug reported regarding potential CAA mis-issuance.
- CA provided logs indicating no CAA records were found.
Participants
Quirin Scheitle
Jeremy Rowley
Gerv
Tim
External References
Similar Local Cases
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
DigiCert: Non-BR-Compliant OCSP Responders
DigiCert: no subject alternative name in Siemens certs
DigiCert: Onion Certs
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address
DigiCert / InfoCert: Insufficient Serial Number Entropy