← GoDaddy cases
Bugzilla #1647030 Ca Certificate Compliance

GoDaddy: Agreed-Upon Website Domain Validation Method Issue

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy disclosed a compliance issue in its certificate issuance process related to Agreed-Upon Website domain validation (WSCv2). GoDaddy stated that on June 10, 2020 around 4:00 PM, a developer performing system updates identified a potential bug where website control validation information for one sub-domain could be automatically used to validate a second sub-domain with the same primary level domain. GoDaddy reported that a newer developer introduced a change while updating documentation for BR section 3.2.2.4.18, adding a new variable for the domain validation method WSCv2; GoDaddy said the developer did not add the new variable to a code method that enforces reuse checks based on prior FQDN matching, causing the system to bypass that check when using the new variable. GoDaddy said it deployed a system patch on June 10 at 8:40 PM, completed 454 revocations on June 11, and confirmed that no more certificates with the problem were issued after processing the revocations. GoDaddy also described remediation steps including coaching and restricting peer reviews to senior engineers, improving change request documentation with engineering review, and adding a system test that runs every 15 minutes to detect the problematic scenario and alert on-call personnel. Mozilla indicated an intent to close the bug on or about 5-Aug-2020 unless additional issues or questions were raised, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.86 4 comments
Chronology
  1. GoDaddy identified a bug in its WSCv2 domain validation reuse logic during system updates.
  2. GoDaddy deployed and verified a patch to correct the pre-verification method.
  3. GoDaddy completed revocation of 454 affected certificates and confirmed no further problematic issuance.
Thread Activity
  1. GoDaddy — Opened the bug with a detailed incident report describing how the WSCv2 variable change bypassed an FQDN reuse check, listing affected certificates and remediation steps.
  2. Mozilla representative — Asked for clarification and questioned whether the FQDN reuse check was omitted when the new variable was added.
  3. GoDaddy — Explained the intended validation/reuse behavior and confirmed the check for the new variable was not added; stated reviews would be done only by senior engineers.
  4. Mozilla representative — Stated an intent to close the bug on or about 5-Aug-2020 unless additional issues or questions were raised.
Participants
GoDaddy Mozilla representative
External References
Similar Local Cases
#1645832 RESOLVED Ca Certificate Compliance Opened 2020-06-15 · Closed 2023-02-22 · 94% similar
GoDaddy: Expired CRLs
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 79% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1662807 RESOLVED Ca Certificate Compliance Opened 2020-09-02 · Closed 2023-02-22 · 78% similar
GoDaddy: Certificates issued with validity periods greater than 398-days
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 78% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1793789 RESOLVED Ca Certificate Compliance Opened 2022-10-05 · Closed 2023-02-22 · 71% similar
Sectigo: Incorrect JOI
#1684112 RESOLVED Ca Certificate Compliance Opened 2020-12-23 · Closed 2023-02-22 · 70% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1672423 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 70% similar
Camerfirma: certificate for unregistered domain cuatis.net
#1676440 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-11-10 · Closed 2023-02-22 · 69% similar
NetLock: Cumulative report connected to EV verification

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action