GoDaddy: Agreed-Upon Website Domain Validation Method Issue
GoDaddy disclosed a compliance issue in its certificate issuance process related to Agreed-Upon Website domain validation (WSCv2). GoDaddy stated that on June 10, 2020 around 4:00 PM, a developer performing system updates identified a potential bug where website control validation information for one sub-domain could be automatically used to validate a second sub-domain with the same primary level domain. GoDaddy reported that a newer developer introduced a change while updating documentation for BR section 3.2.2.4.18, adding a new variable for the domain validation method WSCv2; GoDaddy said the developer did not add the new variable to a code method that enforces reuse checks based on prior FQDN matching, causing the system to bypass that check when using the new variable. GoDaddy said it deployed a system patch on June 10 at 8:40 PM, completed 454 revocations on June 11, and confirmed that no more certificates with the problem were issued after processing the revocations. GoDaddy also described remediation steps including coaching and restricting peer reviews to senior engineers, improving change request documentation with engineering review, and adding a system test that runs every 15 minutes to detect the problematic scenario and alert on-call personnel. Mozilla indicated an intent to close the bug on or about 5-Aug-2020 unless additional issues or questions were raised, and the bug is marked RESOLVED with resolution FIXED.
- GoDaddy identified a bug in its WSCv2 domain validation reuse logic during system updates.
- GoDaddy deployed and verified a patch to correct the pre-verification method.
- GoDaddy completed revocation of 454 affected certificates and confirmed no further problematic issuance.
- GoDaddy — Opened the bug with a detailed incident report describing how the WSCv2 variable change bypassed an FQDN reuse check, listing affected certificates and remediation steps.
- Mozilla representative — Asked for clarification and questioned whether the FQDN reuse check was omitted when the new variable was added.
- GoDaddy — Explained the intended validation/reuse behavior and confirmed the check for the new variable was not added; stated reviews would be done only by senior engineers.
- Mozilla representative — Stated an intent to close the bug on or about 5-Aug-2020 unless additional issues or questions were raised.