← GoDaddy cases
Bugzilla #1662810 Policy Document Issue

GoDaddy: DV certificates with organizationalUnit field in subject

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns GoDaddy-issued DV certificates that assert the DV policy OID (2.23.140.1.2.1) but include an organizationalUnit value in the Subject field. The reporter cited Baseline Requirements 7.1.4.2.2(i) as restricting when the organizationalUnit field can appear and asked GoDaddy to provide an incident response. GoDaddy responded that it does not include names, DBAs, tradenames, trademarks, addresses, locations, or other text referring to a specific natural person or legal entity in the OU field for its DV certificates, and that the OU value used in the examples is “Domain Control Validated,” which GoDaddy stated does not refer to a specific natural person or legal entity. GoDaddy also stated it remains compliant with the Baseline Requirements and will continue to align with any amendments. The reporter then asked for a link/reference to where GoDaddy fulfills the Baseline Requirements requirements related to including an OU, pointing to GoDaddy/Starfield CP/CPS. GoDaddy provided CP/CPS references describing what Starfield verifies for certificate types and showing the OU field output (e.g., “Domain Control Verified”). Mozilla indicated the bug would be scheduled for closure on 12 October 2020, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.86 5 comments
Chronology
  1. Bug opened after concern that GoDaddy DV certificates include an organizationalUnit value in the Subject field.
  2. GoDaddy replied that its OU value (“Domain Control Validated”) does not refer to a specific natural person or legal entity and asserted Baseline Requirements compliance.
  3. Reporter requested a CP/CPS link/reference showing where GoDaddy fulfills OU-related requirements.
  4. GoDaddy provided CP/CPS section references describing verification and OU field output.
  5. Mozilla scheduled the bug for closure.
Thread Activity
  1. Community commenter — Reported that GoDaddy DV certificates include an organizationalUnit in the Subject field and asked for an Incident Response per the Baseline Requirements discussion.
  2. GoDaddy — Explained that GoDaddy’s DV OU field uses “Domain Control Validated,” does not contain personal/legal-entity text, and stated GoDaddy remains compliant.
  3. Community commenter — Disputed the interpretation and asked for a link/reference in GoDaddy’s CP/CPS showing how OU inclusion requirements are fulfilled.
  4. GoDaddy — Provided CP/CPS references (Section 3.2 and Section 10.4) describing verification and showing OU output examples.
  5. Mozilla representative — Indicated no further questions/comments and that the bug would be scheduled for closure on 12 October 2020.
Participants
Community commenter GoDaddy Mozilla representative
Similar Local Cases
#1037907 RESOLVED Policy Document Issue Opened 2014-07-12 · Closed 2022-11-14 · 60% similar
GoDaddy: Valid 1024 certificates
#1819422 RESOLVED Policy Document Issue Opened 2023-02-28 · Closed 2023-03-24 · 58% similar
Certainly: CRL Issuing Distribution Point Mismatch in CCADB
#1793642 RESOLVED Policy Document Issue Opened 2022-10-04 · Closed 2025-07-08 · 57% similar
GoDaddy: CRLs are version 1 and lack CRL Number extension
#1717034 RESOLVED Ca Documents Policy Document Issue Opened 2021-06-17 · Closed 2023-02-22 · 56% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 54% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1650234 RESOLVED Ca Documents Policy Document Issue Opened 2020-07-02 · Closed 2023-02-22 · 54% similar
PKIoverheid / QuoVadis: CPS inconsistencies
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 54% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1713976 RESOLVED Policy Document Issue Opened 2021-06-02 · Closed 2023-02-22 · 54% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action