Possible violation of CAA by nazwa.pl

2018-07-25 Thread michel.lebihan2000--- via dev-security-policy
Hello, My domain registrar who is also a certificate authority just issued a precertificate (visible in CT logs) and a valid certificate for my domain. This is part of their new offer to automatically offer free certificates for all of their domains: https://www.nazwa.pl/certyfikaty-ssl/ I had

T-Systems invalid SANs

2019-02-26 Thread michel.lebihan2000--- via dev-security-policy
Hello, While looking at CT logs, I noticed multiple certificates issued by T-Systems that have SANs that seem invalid. The first certificate I noticed is https://crt.sh/?id=1044575692=ocsp,cablint,zlint The DNS name has a leading /. That certificate was revoked, but I didn't see any report

Re: T-Systems invalid SANs

2019-02-27 Thread michel.lebihan2000--- via dev-security-policy
I also found that certificates that were issued very recently have duplicate SANs: https://crt.sh/?id=1231853308=cablint,x509lint,zlint https://crt.sh/?id=1226557113=cablint,x509lint,zlint https://crt.sh/?id=1225737388=cablint,x509lint,zlint ___

CFCA certificate with invalid domain

2019-02-27 Thread michel.lebihan2000--- via dev-security-policy
Hello, I noticed this certificate https://crt.sh/?id=1231965201=cablint,x509lint,zlint that has an invalid domain `mail.xinhua08.con` in SANs. This looks like a typo and `mail.xinhua08.com` is present in other certificates. Such an issue makes me wonder about the quality of their validation.