My main gripe with Cloudflare is not that they issued these certificates. It's the fact that they are valid for one(1) year and I don't have an easy, preferably automated way to have them revoked.
So it might have been a misconfiguration on porkbuns or cloudflares (or maybe a porkbun feature that requires the cloudflare cert) end that created a cert.
Seems like porkbun should be more clear about that using "their" DNS might lead to cloudflare issuing certs for those domains.
I do trust Cloudflare and Porkbun, but it does feel a little icky to happen without /any/ feedback or being informed.
I’d at least like to see the DNS entries in the Porkbun UI!
Don’t bother going through Cloudflare.
If they don’t respond to you within 24 hours, let me know and we can start an incident against that CA.
I reached out to Digicert at revoke@digicert.com. They responded almost immediately and directed me to Cloudflare's abuse report form, where I was met with a wall. Now I'm back to Digicert asking them to please revoke them.
Note that this isn't an urgent security situation, as the domain in question isn't in use currently. It's more of an annoyance, since the certs are valid for 1 year.
Certificates in question: https://crt.sh/?id=11447235791 https://crt.sh/?id=11447092451