GoDaddy: Issues with State and Country fields
This case describes GoDaddy reporting an incident involving incorrect State/Province and Country information in some issued certificates. GoDaddy stated it received a certificate problem report on August 19, 2019, began investigating the certificates listed, and contacted affected customers and the problem reporter. GoDaddy finalized its resolution path on August 23, 2019 and revoked all affected certificates that evening. GoDaddy reported that it identified 7 certificates issued between October 19, 2017 and June 25, 2019, including cases where the Country field had an incorrect ISO code and cases where US State names were misspelled. GoDaddy explained that while it had automation for state/country correlation in its client-facing UI, it did not have the same correlation and misspelling controls in its Validation Specialist systems, and that Validation Specialists sometimes overrode automation to manually correct requests. GoDaddy stated it deployed new validation controls globally on October 1, 2019, including using a predefined list of acceptable states/provinces and jurisdictions, providing them via a drop-down, removing free-form text fields, and blocking issuance when location data does not match the predefined rules. The bug was marked resolved with resolution FIXED, and a later comment indicated remediation appeared complete.
- GoDaddy received a certificate problem report and began investigating the listed certificates.
- GoDaddy revoked all affected certificates identified in the incident.
- GoDaddy deployed globally new validation automation to mitigate misspellings and incorrect state/province to country correlation.
- GoDaddy — GoDaddy filed an incident report describing the State/Country field problems, investigation steps, and planned remediation.
- Community commenter — Ryan Sleevi asked for clarification on GoDaddy’s awareness, review of other CAs’ approaches, timelines, and reasons for delays in updates.
- GoDaddy — GoDaddy responded that it was following prior discussions, reviewed approaches from CAs that publicly disclosed, and explained its update timeline depended on community consensus about an acceptable source.
- Fastly representative — Wayne Thayer requested a timeline for remediating the class of errors and questioned the adequacy of the incident response timing.
- GoDaddy — GoDaddy described evaluating Google’s GeoCode API and listed concerns about accuracy and localization, stating it would use an internal source for automation.
- Community commenter — Ryan Sleevi commented on concerns about transparency and risk management, and compared GoDaddy’s response to examples from other bugs.
- GoDaddy — GoDaddy stated new controls would be deployed in production no later than end of September and that it would update the thread after deployment.
- GoDaddy — GoDaddy announced that on October 1 it deployed a solution that fully mitigated the issue by using predefined state/province-to-jurisdiction mappings, drop-down selection, removal of free-form fields, and issuance blocking when rules are not met.
- Fastly representative — Wayne Thayer stated it appeared all questions were answered and remediation was complete.