← GoDaddy cases
Bugzilla #1605804
Certificate Problem Report
GoDaddy: Domain Validation Reuse Issue
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy identified a domain validation reuse issue during an internal audit, confirming that a specific DV certificate had been validated over 825 days prior to its issuance. The CA took immediate action, revoking affected certificates and implementing a patch to prevent future occurrences. A total of 35 certificates were identified as problematic, with corrective measures including enhanced oversight and compliance functions to ensure similar issues do not arise again.
Chronology
- Issue reported to compliance and investigation began.
- Issue confirmed and patch work began.
- List of affected NON-EV and EV SSLs confirmed and revoked.
Participants
Joanna
wthayer@fastly.com
bwilson@mozilla.com
External References
Similar Local Cases
GoDaddy: CRL Issuer Mismatch
GoDaddy: failure to revoke underscores
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
GoDaddy: Does not provide a method for domain owners to revoke their certificates
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates