← GoDaddy cases
Bugzilla #1567061
Policy Compliance
GoDaddy: inconsistent disclosure of externally-operated intermediate
RESOLVED
FIXED
GoDaddy
AI Summary
The case involves GoDaddy's inconsistent disclosure regarding cross-certificates that were issued under different Certificate Policies/Certificate Practice Statements (CP/CPS). Initially, GoDaddy disclosed these certificates as being under their CP/CPS, despite the fact that the root certificate controlling them had been transferred to Amazon Trust Services. This led to confusion and concerns about compliance with Mozilla's incident reporting guidelines. GoDaddy has since acknowledged the issue and is working on updating their audit reports to reflect the correct disclosures.
Chronology
- GoDaddy disclosed intermediates operated under the same CP/CPS as parent.
- GoDaddy acknowledged the inquiry and committed to a community response.
- GoDaddy clarified the misunderstanding regarding the cross-certificates.
- GoDaddy submitted updated audit reports for review.
- The issue was deemed resolved from an audit perspective.
Participants
Andrew Ayer
Joanna
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
Amazon Trust Services: CP/CPS does not specify key compromise methods
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
SECOM: CP/CPS does not clearly specify domain validation methods
GoDaddy: Non-BR-Compliant Certificate Issuance
Camerfirma: Outdated audit statements for intermediate certs
PKIoverheid: Missing Intermediate CA from audit statement
FNMT: CP/CPS lack CAA processing details
PKIoverheid: KPN CPS lacks CPR problem reporting instructions