Disclosure of new GoDaddy Code Signing Subordinate CAs
This case is about GoDaddy disclosing newly issued code signing subordinate CAs that were not yet listed in GoDaddy’s repository. The reporter stated that GoDaddy had issued two new subordinate CAs for a code-signing-specific hierarchy and attached them to the bug, noting they are covered under GoDaddy’s CPS and audits. The reporter referenced a May 2014 CA communication request that CAs disclose all non-technically constrained subordinate CAs, and pointed to GoDaddy’s repository URL where the CAs were not yet listed. Kathleen Wilson closed the bug as resolved, while stating the bug would continue to be used to provide information about GoDaddy’s publicly disclosed and audited subordinate CAs not listed on GoDaddy’s website. Later comments indicate additional intermediate certificates were issued for EV code signing and were attached for inclusion in GoDaddy’s repository and CPS. The bug’s resolution is WORKSFORME and its status is RESOLVED.
- GoDaddy issued two new code-signing subordinate CAs intended for a hierarchy specific to code signing.
- Mozilla CA Program closed the disclosure bug as resolved while keeping it available for ongoing subordinate CA information.
- GoDaddy issued two additional EV code signing intermediate certificates and attached them to the bug.
- Community commenter — Created an attachment for two newly issued GoDaddy code-signing subordinate CAs, stating they were not yet listed in GoDaddy’s repository and that they are covered under GoDaddy’s CPS and audits.
- Mozilla representative — Closed the bug as resolved, but said it would continue to be used to provide information about GoDaddy’s publicly disclosed and audited subordinate CAs not listed on GoDaddy’s website.
- Community commenter — Attached additional intermediate certificates for EV code signing, stating they would be added to GoDaddy’s repository and CPS.