GoDaddy: Failure to revoke certificate with compromised key within 24 hours
This case involves GoDaddy's failure to revoke a certificate with a compromised key within the required 24-hour timeframe. The issue was first identified on May 7, 2020, when a certificate problem report was received. GoDaddy conducted an investigation and revoked the certificate on May 8, 2020, but later acknowledged that their interpretation of the revocation requirements was incorrect. Following community feedback, GoDaddy revised its processes to start the revocation timer upon receipt of the problem report. They also reported additional certificates that were revoked under the same incorrect timeframe and developed a timing matrix to improve compliance tracking. The case has been resolved with the implementation of these corrective actions.
- GoDaddy received a certificate problem report indicating a possible key compromise.
- GoDaddy revoked the compromised certificate.
- GoDaddy committed to providing a response to the community regarding the incident.
- GoDaddy shared a timing matrix for compliance with the Baseline Requirements.
- GoDaddy — GoDaddy detailed the timeline of events related to the certificate compromise and revocation.
- GoDaddy — GoDaddy acknowledged the inquiry and committed to a community response.
- GoDaddy — GoDaddy reported 13 additional certificates revoked due to the same issue.
- GoDaddy — GoDaddy attached the timing matrix for compliance tracking.