← GoDaddy cases
Bugzilla #1391429
Policy Compliance
GoDaddy: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy faced issues with the issuance of certificates that were not compliant with the Baseline Requirements (BRs). The problems included invalid DNS names containing leading spaces and double dots. GoDaddy acknowledged these issues and provided a remediation plan, which included revoking problematic certificates and implementing new validation checks to prevent future occurrences. The CA has since confirmed that all certificates are now subject to a linting process before issuance, ensuring compliance with the BRs.
Chronology
- Initial report of non-compliance issues.
- GoDaddy outlines remediation plan.
- Implementation of CabLint for certificate validation.
Participants
Kathleen Wilson
Daymion Reynolds
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
Camerfirma: Govern d'Andorra audits
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
SwissSign: BRs require full annual audits
Actalis: Non-BR-Compliant Certificate Issuance
Izenpe: Non-BR-Compliant Certificate Issuance
Entrust: Non-BR-Compliant Certificate Issuance
QuoVadis: Non-BR-Compliant Certificate Issuance
SECOM: Non-BR-Compliant Certificate Issuance