← GoDaddy cases
Bugzilla #1647030
Certificate Problem Report
GoDaddy: Agreed-Upon Website Domain Validation Method Issue
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy identified a bug in their domain validation process where validation information from one sub-domain was incorrectly used to validate another sub-domain under the same primary domain. This issue was discovered on June 10, 2020, during system updates, leading to the revocation of 454 affected certificates issued between May 27 and June 10, 2020. The problem arose due to a coding oversight when a new variable was introduced without updating the necessary validation checks. GoDaddy has since implemented corrective measures to prevent future occurrences.
Chronology
- A developer introduced a bug while processing a change request.
- Developers became aware of the bug and defined the population of affected certificates.
- Completed revocations of the affected certificates.
Participants
Daniela Hood
Ben Wilson
External References
Similar Local Cases
GoDaddy: Document Reuse Issue
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
GoDaddy: OV Documentation Reuse
GoDaddy: Expired CRLs
GoDaddy: CA Certificates with HTTPS URL in AIA Field
Sectigo: Mojibake in certificate Subject fields
GoDaddy: Root CRLs exceed maximum validity period by 1 second
GoDaddy: Domain Validation Reuse Issue