← GoDaddy cases
Bugzilla #1533774
Incident
GoDaddy: Insufficient serial number entropy
RESOLVED
FIXED
GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GoDaddy identified a compliance issue regarding the entropy of certificate serial numbers, discovering that over 12,000 live certificates did not meet the 64-bit requirement. The issue was first noted on March 6, 2019, following discussions in the mozilla.dev.security.policy group. GoDaddy deployed a fix on March 7, 2019, and ceased issuing certificates with the defect. They also began revoking affected certificates, with a timeline for completion communicated to stakeholders. The CA has since updated its processes to ensure compliance with the Baseline Requirements.
Chronology
- GoDaddy began researching the insufficient serial number entropy issue.
- GoDaddy deployed a fix to address the serial number issue.
- GoDaddy reported the number of affected certificates was revised to approximately 12,152.
Thread Activity
- Fastly representative — Daymion Reynolds posted about the serial number issue and the timeline of actions taken.
- Community commenter — Inquired about updates on the list of impacted certificates.
- GoDaddy — Updated the count of impacted certificates and outlined the steps taken.
- Fastly representative — Proposed to close the bug as 'Fixed' due to conflicting evidence.
Participants
Community commenter
External References
Similar Local Cases
GoDaddy: Edge Case for Data Reuse Outside of Timeframes
GoDaddy: Does not provide a method for domain owners to revoke their certificates
DigiCert: "Some-State" in stateOrProvinceName
GoDaddy: Revocation process is unusable due to contact address not accepting attachments
HARICA: 3 EV TLS Certificates without L or ST
PKIoverheid: KPN Insufficient Serial Number Entropy
Izenpe: Non-BR-Compliant Certificate Issuance
Sectigo: Forbidden Domain Validation Method