GoDaddy: Expired CRLs
GoDaddy reported an incident involving expired Certificate Revocation Lists (CRLs) that occurred on June 3, 2020. The issue was identified after a customer inquiry prompted an investigation, revealing that the CRLs had not been updated due to a failure in the migration process to a new environment. GoDaddy took immediate action by regenerating and publishing new CRLs on June 4, 2020. The CA has since improved its procedures for system transitions and is migrating the CRL generation process to a clustered environment to prevent future occurrences. The case has been resolved with the implementation of these corrective measures.
- CRLs expired
- New CRLs published
- GoDaddy — GoDaddy explains the timeline and actions taken regarding the expired CRLs.
- Community commenter — Concerns raised about the lack of detail in the incident report.
- GoDaddy — Response detailing the standard procedures followed during the incident.
- GoDaddy — GoDaddy outlines its disaster recovery procedures but declines to disclose specifics for security reasons.
- GoDaddy — Attached a sanitized excerpt from the operations guide related to disaster recovery.
- Mozilla representative — Reviewed the Disaster Recovery Guide and indicated no further questions.