← GoDaddy cases
Bugzilla #1330482
Certificate Misissuance
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
RESOLVED
INCOMPLETE
GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves a report of incorrect certificate issuance by GoDaddy, which appears to be a regression of a similar issue reported in 2010. The user detailed steps to reproduce the problem, indicating that domain verification could be bypassed due to misconfigurations. Mozilla's team discussed whether this issue was separate from ongoing investigations and acknowledged the need for GoDaddy to implement preventative measures. The bug was ultimately resolved and made public after confirming that it was no longer actionable.
Chronology
- User reported a new incorrect issuance bug related to GoDaddy's certificate verification process.
- Bug was closed and made public after confirming no further action was needed.
Thread Activity
- Fredemmott representative — User reported a regression of a previous issue with GoDaddy's certificate issuance.
- Mozilla representative — Inquired if this issue was separate from another ongoing investigation.
- Mozilla representative — Indicated the bug was no longer actionable and recommended closing it.
Participants
Fredemmott representative
Mozilla representative
External References
Similar Local Cases
GoDaddy: Non-BR-Compliant Certificate Issuance
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
GoDaddy: Misissuance of Cross Signed Certs
Visa: Issuing 1024 bit certificates
Camerfirma: Non-BR-Compliant Certificate Issuance
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates