GoDaddy: Valid 1024 certificates
The case was raised by an external party who reported that GoDaddy had a large number of still-valid, unrevoked 1024-bit certificates, including certificates issued by the intermediate CA “Go Daddy Secure Certification Authority.” The reporter stated that about 11,000 certificates were still valid and not revoked, and that at least about 350 were still in use. GoDaddy’s representative responded that the 1024-bit certificates were issued prior to the BR 1.0 effective date (01-Jul-12) and therefore were not subject to the BR Appendix A key requirements, and asked for any evidence of newly issued 1024-bit certificates in violation of the Baseline Requirements. The reporter disagreed with the interpretation that Appendix A only applies to certificates generated after the effective date, arguing it should apply to all subscriber certificates, while noting an exception for root certificates generated before 31 December 2010. The thread referenced a prior CA/B Forum discussion where Kathleen agreed that BRs effectively cover only certificates issued after the effective date, and that continued 1024-bit support was not guaranteed but was not a BR compliance problem. A Mozilla participant concluded that, given the cited interpretation, there was no BR compliance problem in this case, and the bug was resolved as INVALID.
- An external party reported that GoDaddy had many still-valid, unrevoked 1024-bit certificates.
- GoDaddy responded that the certificates were issued before the BR 1.0 effective date and questioned whether any newly issued 1024-bit certificates existed in violation.
- Mozilla stated that, under the referenced interpretation, there was no BR compliance problem and the issue was treated as not applicable.
- Roeckx representative — Reported a list of about 11,000 still-valid, not-revoked 1024-bit GoDaddy certificates and identified the intermediate CA that issued them.
- GoDaddy — Argued the 1024-bit certificates were issued before BR 1.0 effective date (01-Jul-12) and therefore were not subject to Appendix A key requirements, and asked for evidence of newly issued violating certificates.
- Roeckx representative — Disagreed that Appendix A only applies after the effective date and cited the exception for root certificates generated before 31 December 2010.
- GoDaddy — Referenced a CA/B Forum discussion where Kathleen agreed that BRs effectively cover only certs issued after the effective date, and noted continued 1024-bit support was not guaranteed.
- Roeckx representative — Pointed to a statement that no party should expect continued support for RSA key sizes smaller than 2048 bits past December 31, 2013.
- Mozilla representative — Concluded that, given the interpretation and the certificate dates, there was no BR compliance problem, though GoDaddy could face issues when browsers stop accepting 1024-bit certificates.