GoDaddy: Random Value Vulnerability in Domain Validation Method
GoDaddy disclosed a self-identified vulnerability in its domain validation code that could allow validation controls to be bypassed. The issue involved a “Random Value” generated for Method 3.2.2.4.6 and 3.2.2.4.7 being validated using Method 3.2.2.4.2 by persons who were not confirmed as the domain contact. GoDaddy stated the bug was introduced in November 2014 and was leveraged to issue a total of 865 certificates. GoDaddy reported that it closed the defect hours after identification and began scope and revocation activities in parallel. It stated that, in accordance with CA/B Forum BR section 4.9.1.1, all mis-issued certificates were revoked within 24 hours of identification, with revocation actions and follow-on identification described across 8/13–8/16. GoDaddy also said it updated its incident management process to include the discovered use case for any potential future incident. The bug is marked RESOLVED with resolution FIXED.
- GoDaddy stated the vulnerability was introduced in its validation code.
- GoDaddy identified the vulnerability as a possible revocation event and began scoping and revocation.
- GoDaddy reported that all certificates were revoked, with further research identifying additional affected certificates.
- GoDaddy reported additional certificates were identified and customers were notified of pending revocation.
- GoDaddy reported all certificates were revoked after additional identification.
- GoDaddy posted the incident report request and disclosed the incident details in this Bugzilla case.
- Fastly representative — Wayne Thayer posted a request for an incident report and included GoDaddy’s disclosure that self-audits found a validation-bypass vulnerability affecting 865 certificates and that mis-issued certificates were revoked within 24 hours.
- GoDaddy — Daymion Reynolds provided a structured incident-report response including the revocation timeline, stated the bug was closed hours after identification, and described the defect as introduced in November 2014 due to an oversight.
- Community commenter — Ryan Sleevi asked for more details about how the defect scenario would work and requested clarification on incident management and the “further research” gap.
- Community commenter — Ryan Sleevi asked whether there were any updates.
- GoDaddy — Daymion Reynolds replied that the scenario described would not have been possible for an attacker, explained how Random Values were generated and distributed, and said GoDaddy updated its incident management process to include the use case.