GoDaddy: Non-BR-Compliant Certificate Issuance
This case concerns certificates issued by GoDaddy that were reported as non-compliant with Mozilla’s Baseline Requirements. The issues included failure to respond within 24 hours after a Problem Report was submitted and invalid dnsNames, including leading spaces in DNS names and double-dots (empty labels) within dnsNames. GoDaddy stated it became aware of the problems via a call to its support team on 30 July 2017, identified handling errors while reviewing the MDSP list on 1 Aug 2017, and revoked the reported certificates on 2 Aug 2017 and 3 Aug 2017. GoDaddy reported that it stopped issuance of certificates containing a space in the CN or any SAN field by updating its system to prevent issuance of such certificates, and it said it added explicit validation for whitespace characters within domain names. GoDaddy also stated that it corrected its system to check for empty-labels within DNS names and that it planned to deploy certlint-based preissuance checks by 30 Nov 2017. The bug was later updated to indicate that CabLint (certlint solution) was implemented on 11/30/2017 and that certificates provisioned by the system are now linted and will not be issued unless they pass the lint test, and the bug was marked RESOLVED with resolution FIXED.
- GoDaddy received a call reporting the certificate issue to its support team.
- GoDaddy identified an error in handling the problem report while reviewing the MDSP list.
- GoDaddy revoked the 5 reported certificates and identified additional unrevoked certificates containing spaces.
- GoDaddy revoked the remaining 4 certificates containing spaces.
- GoDaddy implemented CabLint/certlint-based preissuance checks so certificates are linted before issuance.
- Mozilla representative — Opened the bug requesting GoDaddy provide information about how it became aware of the reported problems, confirm it stopped issuing problematic certificates, list affected certificates, explain root causes, and describe remediation steps and timelines.
- Community commenter — Provided GoDaddy’s remediation details, including awareness timeline, confirmation of stopping issuance of certificates with spaces in CN/SAN, counts and issuance date range for certificates with spaces, and explanation that whitespace within domain names was not removed by existing logic.
- Community commenter — Attached a list of issued certificates containing spaces in the domain name.
- Community commenter — Attached a list of issued certificates with double-dots in the dnsName and corrected the count of certificates affected.
- Community commenter — Asked for clarification on whether GoDaddy would implement RFC 1034/RFC 5280-compliant validation and requested more detailed root-cause explanation for the double-dots/empty-label issue.
- Community commenter — Clarified that the RFC 1034 validation regex was incomplete (not checking for spaces) and stated the root cause for empty-labels was inadequate verification of domain name input from CSRs, with an explanation of how older certificates were validated.
- Community commenter — Summarized the issues and remediation plan and set a Needs-Info flag to prompt GoDaddy for updates on the proposed prevention mechanism deployment.
- Community commenter — Confirmed the summary was correct and said GoDaddy would update the bug when the certlint-based preissuance check was in place.
- Mozilla representative — Reassigned the bug to a new GoDaddy rep.
- GoDaddy — Reported that CabLint was implemented as the certlint solution and that certificates provisioned by the system are linted and will not be issued unless they pass the lint test.