GoDaddy: Certificates issued with validity periods greater than 398-days
GoDaddy disclosed that it had issued certificates with validity periods exceeding the 398-day limit established by the CA/Browser Forum's Ballot SC31, effective September 1, 2020. The CA became aware of the issue through its internal problem reporting mechanism and took immediate action by reissuing and revoking the affected certificates. GoDaddy has committed to improving its compliance processes and has implemented organizational changes to prevent future incidents. The case has been resolved with the CA confirming that it has ceased issuing certificates that violate the new validity period requirement.
- GoDaddy became aware of the certificate validity issue.
- GoDaddy reissued and revoked the affected certificates.
- GoDaddy completed control verifications and implemented new governance processes.
- Community commenter — Noted that GoDaddy had issued certificates violating the new validity period requirement.
- GoDaddy — Provided a timeline of actions taken by GoDaddy in response to the incident.
- GoDaddy — Reported that control verifications were complete and no further gaps were identified.