← GoDaddy cases
Bugzilla #1037907 Policy Document Issue

GoDaddy: Valid 1024 certificates

RESOLVED INVALID GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case was raised by an external party who reported that GoDaddy had a large number of still-valid, unrevoked 1024-bit certificates, including certificates issued by the intermediate CA “Go Daddy Secure Certification Authority.” The reporter stated that about 11,000 certificates were still valid and not revoked, and that at least about 350 were still in use. GoDaddy’s representative responded that the 1024-bit certificates were issued prior to the BR 1.0 effective date (01-Jul-12) and therefore were not subject to the BR Appendix A key requirements, and asked for any evidence of newly issued 1024-bit certificates in violation of the Baseline Requirements. The reporter disagreed with the interpretation that Appendix A only applies to certificates generated after the effective date, arguing it should apply to all subscriber certificates, while noting an exception for root certificates generated before 31 December 2010. The thread referenced a prior CA/B Forum discussion where Kathleen agreed that BRs effectively cover only certificates issued after the effective date, and that continued 1024-bit support was not guaranteed but was not a BR compliance problem. A Mozilla participant concluded that, given the cited interpretation, there was no BR compliance problem in this case, and the bug was resolved as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 13:58 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.86 6 comments
Chronology
  1. An external party reported that GoDaddy had many still-valid, unrevoked 1024-bit certificates.
  2. GoDaddy responded that the certificates were issued before the BR 1.0 effective date and questioned whether any newly issued 1024-bit certificates existed in violation.
  3. Mozilla stated that, under the referenced interpretation, there was no BR compliance problem and the issue was treated as not applicable.
Thread Activity
  1. Roeckx representative — Reported a list of about 11,000 still-valid, not-revoked 1024-bit GoDaddy certificates and identified the intermediate CA that issued them.
  2. GoDaddy — Argued the 1024-bit certificates were issued before BR 1.0 effective date (01-Jul-12) and therefore were not subject to Appendix A key requirements, and asked for evidence of newly issued violating certificates.
  3. Roeckx representative — Disagreed that Appendix A only applies after the effective date and cited the exception for root certificates generated before 31 December 2010.
  4. GoDaddy — Referenced a CA/B Forum discussion where Kathleen agreed that BRs effectively cover only certs issued after the effective date, and noted continued 1024-bit support was not guaranteed.
  5. Roeckx representative — Pointed to a statement that no party should expect continued support for RSA key sizes smaller than 2048 bits past December 31, 2013.
  6. Mozilla representative — Concluded that, given the interpretation and the certificate dates, there was no BR compliance problem, though GoDaddy could face issues when browsers stop accepting 1024-bit certificates.
Participants
Roeckx representative GoDaddy Mozilla representative
External References
Similar Local Cases
#1662810 RESOLVED Policy Document Issue Opened 2020-09-02 · Closed 2023-02-22 · 60% similar
GoDaddy: DV certificates with organizationalUnit field in subject
#1793642 RESOLVED Policy Document Issue Opened 2022-10-04 · Closed 2025-07-08 · 57% similar
GoDaddy: CRLs are version 1 and lack CRL Number extension
#708229 RESOLVED Common Ca Database Repository Issue Opened 2011-12-07 · Closed 2022-11-14 · 53% similar
GoDaddy's intermediate CA not in the Mozilla CA bundle
#1742602 RESOLVED Certificate Problem Report Opened 2021-11-23 · Closed 2023-02-22 · 45% similar
GoDaddy: Reported TLS Certificate Private Key Exposure
#1829024 RESOLVED Ca Certificate Compliance Opened 2023-04-19 · Closed 2023-05-05 · 44% similar
GoDaddy: CRL Issuer Mismatch
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 44% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#1904748 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 43% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
#1015767 RESOLVED Certificate Misissuance Opened 2014-05-25 · Closed 2022-11-14 · 42% similar
startcom: still issuing < 2048 bit certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action