← GoDaddy cases
Bugzilla #1391429 Certificate Misissuance Revocation Issue

GoDaddy: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by GoDaddy that were reported as non-compliant with Mozilla’s Baseline Requirements. The issues included failure to respond within 24 hours after a Problem Report was submitted and invalid dnsNames, including leading spaces in DNS names and double-dots (empty labels) within dnsNames. GoDaddy stated it became aware of the problems via a call to its support team on 30 July 2017, identified handling errors while reviewing the MDSP list on 1 Aug 2017, and revoked the reported certificates on 2 Aug 2017 and 3 Aug 2017. GoDaddy reported that it stopped issuance of certificates containing a space in the CN or any SAN field by updating its system to prevent issuance of such certificates, and it said it added explicit validation for whitespace characters within domain names. GoDaddy also stated that it corrected its system to check for empty-labels within DNS names and that it planned to deploy certlint-based preissuance checks by 30 Nov 2017. The bug was later updated to indicate that CabLint (certlint solution) was implemented on 11/30/2017 and that certificates provisioned by the system are now linted and will not be issued unless they pass the lint test, and the bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:07 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.86 10 comments
Chronology
  1. GoDaddy received a call reporting the certificate issue to its support team.
  2. GoDaddy identified an error in handling the problem report while reviewing the MDSP list.
  3. GoDaddy revoked the 5 reported certificates and identified additional unrevoked certificates containing spaces.
  4. GoDaddy revoked the remaining 4 certificates containing spaces.
  5. GoDaddy implemented CabLint/certlint-based preissuance checks so certificates are linted before issuance.
Thread Activity
  1. Mozilla representative — Opened the bug requesting GoDaddy provide information about how it became aware of the reported problems, confirm it stopped issuing problematic certificates, list affected certificates, explain root causes, and describe remediation steps and timelines.
  2. Community commenter — Provided GoDaddy’s remediation details, including awareness timeline, confirmation of stopping issuance of certificates with spaces in CN/SAN, counts and issuance date range for certificates with spaces, and explanation that whitespace within domain names was not removed by existing logic.
  3. Community commenter — Attached a list of issued certificates containing spaces in the domain name.
  4. Community commenter — Attached a list of issued certificates with double-dots in the dnsName and corrected the count of certificates affected.
  5. Community commenter — Asked for clarification on whether GoDaddy would implement RFC 1034/RFC 5280-compliant validation and requested more detailed root-cause explanation for the double-dots/empty-label issue.
  6. Community commenter — Clarified that the RFC 1034 validation regex was incomplete (not checking for spaces) and stated the root cause for empty-labels was inadequate verification of domain name input from CSRs, with an explanation of how older certificates were validated.
  7. Community commenter — Summarized the issues and remediation plan and set a Needs-Info flag to prompt GoDaddy for updates on the proposed prevention mechanism deployment.
  8. Community commenter — Confirmed the summary was correct and said GoDaddy would update the bug when the certlint-based preissuance check was in place.
  9. Mozilla representative — Reassigned the bug to a new GoDaddy rep.
  10. GoDaddy — Reported that CabLint was implemented as the certlint solution and that certificates provisioned by the system are linted and will not be issued unless they pass the lint test.
Participants
Mozilla representative GoDaddy Community commenter
Similar Local Cases
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 97% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
#1330482 RESOLVED Certificate Misissuance Opened 2017-01-12 · Closed 2023-02-22 · 95% similar
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 84% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1391058 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 84% similar
PROCERT: Non-BR-Compliant Certificate Issuance
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 84% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action