← GoDaddy cases
Bugzilla #1605804 Self Reported Incident

GoDaddy: Domain Validation Reuse Issue

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported a potential compliance issue discovered during an internal 3% audit involving a specific DV certificate. GoDaddy confirmed that the DV certificate had been validated more than 825 days prior to issuance, and began compliance and engineering work to address the problem. GoDaddy stopped issuing certificates with the problem on 2019-12-18, deployed a patch the same day, and contacted customers to attempt rekeying. GoDaddy worked to identify affected certificates, confirmed affected EV and non-EV SSL certificates, and revoked the affected certificates on 2019-12-20 and 2019-12-21. The thread states that the root cause was program logic that determined domain-validation-reuse timeframes based on time-of-validation to time-of-certificate-request rather than time-of-validation to time-of-certificate-issuance. GoDaddy’s resolution is marked FIXED in the bug status.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.90 5 comments
Chronology
  1. GoDaddy identified a potential DV certificate issue during an internal 3% audit.
  2. GoDaddy confirmed the DV certificate validation age issue and began remediation, including deploying a patch and revoking the specific certificate.
  3. GoDaddy revoked lists of affected non-EV SSL certificates and then revoked affected EV SSL certificates after confirming them.
  4. GoDaddy revoked remaining affected EV SSL certificates.
Thread Activity
  1. GoDaddy — GoDaddy provided an incident report describing how it discovered the issue, the timeline of investigation and remediation, the number of affected certificates, and the stated root cause and prevention steps.
  2. Fastly representative — Fastly asked GoDaddy to explain more about the root cause and how it was introduced in 2018, and what steps would prevent recurrence.
  3. GoDaddy — GoDaddy acknowledged the inquiry and said it would provide a response by January 7, 2020 due to holidays.
  4. GoDaddy — GoDaddy responded with details on the program logic, stated that it could not provide the exact historical team discussion, and described increased diligence and added checks (including a linter check) and a compliance function aligned with development.
  5. Mozilla representative — Mozilla stated it had no further questions and asked if anyone else had any.
Participants
GoDaddy Fastly representative Mozilla representative
Similar Local Cases
#1577913 RESOLVED Self Reported Incident Opened 2019-08-30 · Closed 2023-02-22 · 97% similar
GoDaddy: Issues with State and Country fields
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 96% similar
GoDaddy: cross certificate disclosure to CCADB
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 89% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#1731939 RESOLVED Self Reported Incident Opened 2021-09-22 · Closed 2023-02-22 · 87% similar
GoDaddy: Issued EV Wildcard Certificate
#1734265 RESOLVED Self Reported Incident Opened 2021-10-06 · Closed 2023-02-22 · 87% similar
GoDaddy: Root CRLs exceed maximum validity period by 1 second
#1462844 RESOLVED Self Reported Incident Revocation Issue Opened 2018-05-19 · Closed 2023-02-22 · 86% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#2002402 RESOLVED Self Reported Incident Opened 2025-11-25 · Closed 2026-01-13 · 82% similar
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB
#2004845 RESOLVED Self Reported Incident Opened 2025-12-09 · Closed 2026-02-11 · 81% similar
GoDaddy: CA Certificates Published in PEM format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action