GoDaddy: Failure to revoke key-compromised certificates within 24 hours
This case concerns GoDaddy certificates that were reported as key-compromised via certificate problem reports sent to p**********s@starfieldtech.com. The reports requested revocation of all certificates issued by GoDaddy using specified SPKI values, and each included a URL of a CSR attesting to the private key compromise. The reporter found that one or more certificates for each SPKI were not revoked within 24 hours of the certificate problem report being received, based on revocation timestamps in validly signed OCSP responses. An addendum states that an additional eight key-compromise certificate problem reports also failed to result in revocation within 24 hours. GoDaddy later indicated that another incident related to the issue was opened in bug 1640310 and asked this bug to be closed as it was being addressed there. The Mozilla reviewer ultimately marked this bug as a duplicate of bug 1640310.
- A first set of key-compromise certificate problem reports was sent requesting revocation of GoDaddy certificates for specified SPKI values.
- Additional key-compromise certificate problem reports were sent requesting revocation of GoDaddy certificates for specified SPKI values.
- GoDaddy opened a related incident in bug 1640310 and requested closure of this bug.
- Mozilla marked this bug as a duplicate of bug 1640310.
- Hezmatt representative — Reported that multiple key-compromise certificate problem reports did not lead to revocation within 24 hours, with timing details based on OCSP revocation timestamps.
- Hezmatt representative — Added that eight further key-compromise reports also failed to result in revocation within 24 hours, including time-to-revoke figures.
- GoDaddy — Said GoDaddy opened another incident related to the issue in bug 1640310 and asked this bug be closed because it was being addressed there.
- Community commenter — Commented that they could not find the referenced bug.
- GoDaddy — Re-shared the link to bug 1640310.
- Community commenter — Asked whether they had overlooked anything and whether the root issue seemed the same.
- Hezmatt representative — Responded that they could not confirm the root issue and noted the linked incident report did not enumerate the certificates listed in this bug.
- GoDaddy — Stated GoDaddy disclosed all 13 certificates mentioned here in bug 1640310 and said the cause was rooted as the same as the one in the other bug.
- Mozilla representative — Marked this bug as a duplicate of bug 1640310.