← GoDaddy cases
Bugzilla #1330482
Certificate Problem Report
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
RESOLVED
GoDaddy
AI Summary
This case addresses a regression in GoDaddy's certificate issuance process, which mirrors a previously reported issue from 2010. The user reported that GoDaddy's verification process allowed for incorrect certificate issuance under certain conditions, similar to past vulnerabilities. The case was resolved after discussions highlighted the need for GoDaddy to implement better preventative measures to avoid such regressions in the future.
Chronology
- Bug reported by user
- Bug closed and made public
Participants
Fred Emmott
Kathleen Wilson
Gervase Markham
Ryan Sleevi
External References
Similar Local Cases
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
Camerfirma: Non-BR-Compliant Certificate Issuance
Visa: Non-BR-Compliant Certificate Issuance
Consorci AOC: Non-BR-Compliant Certificate Issuance
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GoDaddy: failure to revoke underscores