← GoDaddy cases
Bugzilla #1639798
Certificate Problem Report
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
RESOLVED
DUPLICATE
GoDaddy
AI Summary
This case involves GoDaddy's failure to revoke certificates that were reported as compromised within the required 24-hour timeframe. Multiple certificate problem reports were submitted between April 30 and May 11, 2020, detailing the compromise and requesting revocation. Despite these reports, revocation did not occur within the stipulated period, leading to further concerns about compliance with security protocols. An additional eight reports were noted later, indicating ongoing issues with timely revocation.
Chronology
- First certificate problem report submitted.
- Last of the initial reports submitted.
- Related incident opened.
- Bug marked as a duplicate of another case.
Participants
mpalmer@hezmatt.org
jfox@godaddy.com
dxhood@godaddy.com
ryan.sleevi@gmail.com
bwilson@mozilla.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Sectigo: Failure to revoke key-compromised certificate within 24 hours
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
SwissSign: failure to provide a preliminary report within 24 hours
Asseco DS / Certum: Incorrect OCSP response encoding
GoDaddy: CRL Issuer Mismatch
GlobalSign: Failure to revoke key-compromised certificate within 24 hours
Sectigo: Failure to properly respond to a report of subscriber key compromise
GoDaddy: Does not provide a method for domain owners to revoke their certificates