← GoDaddy cases
Bugzilla #1567061 Self Reported Incident Repository Issue

GoDaddy: inconsistent disclosure of externally-operated intermediate

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns GoDaddy’s disclosure in CCADB of cross-certificates that were issued by a GoDaddy root and later affected by a root transfer to Amazon Trust Services. The reporter noted that GoDaddy had disclosed two cross-certificates as being operated under the same CP/CPS as the parent, but that the same subject + SPKI appeared in an Amazon Trust Services root certificate with a different CP/CPS. GoDaddy explained that the cross-certificates were issued by a GoDaddy root still bound to the GoDaddy CP/CPS and CCADB, and that the referenced root certificate was transferred to Amazon later, which is why the cross-certificates remained listed under GoDaddy’s CP/CPS while the root was under Amazon’s CP/CPS. The reporter and Mozilla community indicated that the cross-certificates should be included in Appendix A of GoDaddy’s audit reports and that CCADB disclosures should be audited for correctness. GoDaddy stated it would work with its auditors to update the audit reports and to audit CCADB information, and later submitted updated audit reports for review in Bug 1572234. A later participant stated that the GoDaddy audit reports now include these certificates and viewed the issue as resolved from an audit perspective, while noting that Mozilla policy is unclear on CP/CPS disclosure requirements for cross-certificates and that a CCADB issue was filed to track clarification.

Model: gpt-5.4-nano Generated: 2026-06-13 18:18 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 8 comments
Chronology
  1. GoDaddy disclosed cross-certificates in CCADB under a CP/CPS that the reporter said conflicted with an Amazon Trust Services root’s CP/CPS.
  2. GoDaddy acknowledged a misunderstanding and committed to updating audit disclosures and auditing CCADB information for correctness.
  3. GoDaddy submitted updated audit reports for review in Bug 1572234.
  4. A participant reported that the audit reports now include the certificates and considered the issue resolved, while filing a CCADB clarification issue.
Thread Activity
  1. Mm representative — Andrew Ayer reported that GoDaddy disclosed two intermediates under the same CP/CPS as the parent, but that the same subject+SPKI was found in an Amazon Trust Services root certificate with a different CP/CPS.
  2. GoDaddy — Joanna (GoDaddy) acknowledged the inquiry and said GoDaddy would provide a community response by July 26.
  3. GoDaddy — Joanna explained the cross-certificates were issued by GoDaddy as cross-certificates signed by GoDaddy-controlled roots, and that Amazon Trust Services acquired the referenced root in 2015 and now operates it under Amazon’s CP/CPS.
  4. Community commenter — Ryan Sleevi asked whether GoDaddy should have disclosed both cross-certificates under Amazon’s audit and CP/CPS in CCADB, and suggested reviewing GoDaddy’s CCADB disclosures for correctness.
  5. Mm representative — Andrew Ayer requested an update per Mozilla incident response guidelines because GoDaddy had not responded for a week.
  6. GoDaddy — Joanna clarified that the cross-certificates were issued by a GoDaddy root still bound to GoDaddy CP/CPS/CCADB, while the root certificate was transferred to Amazon later; she agreed cross-certificates should be included in Appendix A and that CCADB should be audited, and said GoDaddy was working with auditors on updates.
  7. GoDaddy — Joanna stated GoDaddy submitted updated audit reports for review and pointed to Bug 1572234 for details.
  8. Fastly representative — W. Thayer said the audit reports now include these certificates and viewed the issue as resolved from an audit perspective, while noting policy ambiguity and referencing a CCADB issue for clarification.
Participants
Mm representative GoDaddy Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 88% similar
GoDaddy: cross certificate disclosure to CCADB
#1577913 RESOLVED Self Reported Incident Opened 2019-08-30 · Closed 2023-02-22 · 83% similar
GoDaddy: Issues with State and Country fields
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 74% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#1462844 RESOLVED Self Reported Incident Revocation Issue Opened 2018-05-19 · Closed 2023-02-22 · 73% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1605804 RESOLVED Self Reported Incident Opened 2019-12-24 · Closed 2023-02-22 · 73% similar
GoDaddy: Domain Validation Reuse Issue
#2055120 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2026-07-15 Still Open · 71% similar
Chunghwa Telecom: Incomplete disclosure of CRL URLs in CCADB
#2047866 RESOLVED Ccadb Metadata Update Ccadb Disclosure Issue Remediation Tracking Opened By Ca Opened 2026-06-16 · Closed 2026-07-21 · 70% similar
certSIGN: incorrect URL in CCADB
#2050850 ASSIGNED Ca Certificate Compliance Common Ca Database Ccadb Disclosure Issue Policy Document Issue Opened 2026-06-26 Still Open · 68% similar
Asseco DS / Certum: HTTP 404 returned by CRL Distribution Point URLs for six pre-inclusion Root CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action