GoDaddy: inconsistent disclosure of externally-operated intermediate
This case concerns GoDaddy’s disclosure in CCADB of cross-certificates that were issued by a GoDaddy root and later affected by a root transfer to Amazon Trust Services. The reporter noted that GoDaddy had disclosed two cross-certificates as being operated under the same CP/CPS as the parent, but that the same subject + SPKI appeared in an Amazon Trust Services root certificate with a different CP/CPS. GoDaddy explained that the cross-certificates were issued by a GoDaddy root still bound to the GoDaddy CP/CPS and CCADB, and that the referenced root certificate was transferred to Amazon later, which is why the cross-certificates remained listed under GoDaddy’s CP/CPS while the root was under Amazon’s CP/CPS. The reporter and Mozilla community indicated that the cross-certificates should be included in Appendix A of GoDaddy’s audit reports and that CCADB disclosures should be audited for correctness. GoDaddy stated it would work with its auditors to update the audit reports and to audit CCADB information, and later submitted updated audit reports for review in Bug 1572234. A later participant stated that the GoDaddy audit reports now include these certificates and viewed the issue as resolved from an audit perspective, while noting that Mozilla policy is unclear on CP/CPS disclosure requirements for cross-certificates and that a CCADB issue was filed to track clarification.
- GoDaddy disclosed cross-certificates in CCADB under a CP/CPS that the reporter said conflicted with an Amazon Trust Services root’s CP/CPS.
- GoDaddy acknowledged a misunderstanding and committed to updating audit disclosures and auditing CCADB information for correctness.
- GoDaddy submitted updated audit reports for review in Bug 1572234.
- A participant reported that the audit reports now include the certificates and considered the issue resolved, while filing a CCADB clarification issue.
- Mm representative — Andrew Ayer reported that GoDaddy disclosed two intermediates under the same CP/CPS as the parent, but that the same subject+SPKI was found in an Amazon Trust Services root certificate with a different CP/CPS.
- GoDaddy — Joanna (GoDaddy) acknowledged the inquiry and said GoDaddy would provide a community response by July 26.
- GoDaddy — Joanna explained the cross-certificates were issued by GoDaddy as cross-certificates signed by GoDaddy-controlled roots, and that Amazon Trust Services acquired the referenced root in 2015 and now operates it under Amazon’s CP/CPS.
- Community commenter — Ryan Sleevi asked whether GoDaddy should have disclosed both cross-certificates under Amazon’s audit and CP/CPS in CCADB, and suggested reviewing GoDaddy’s CCADB disclosures for correctness.
- Mm representative — Andrew Ayer requested an update per Mozilla incident response guidelines because GoDaddy had not responded for a week.
- GoDaddy — Joanna clarified that the cross-certificates were issued by a GoDaddy root still bound to GoDaddy CP/CPS/CCADB, while the root certificate was transferred to Amazon later; she agreed cross-certificates should be included in Appendix A and that CCADB should be audited, and said GoDaddy was working with auditors on updates.
- GoDaddy — Joanna stated GoDaddy submitted updated audit reports for review and pointed to Bug 1572234 for details.
- Fastly representative — W. Thayer said the audit reports now include these certificates and viewed the issue as resolved from an audit perspective, while noting policy ambiguity and referencing a CCADB issue for clarification.