GoDaddy: Root CRLs exceed maximum validity period by 1 second
GoDaddy reported that its root CRLs for GoDaddy and Starfield were issued with a validity period of 365 days and 1 second, which it said could violate the Baseline Requirements CRL issuance frequency requirement that the nextUpdate value must not be more than twelve months beyond the thisUpdate value. GoDaddy stated that its PKI Compliance team discovered the issue after reviewing Bug 1731164 and confirmed on 09/23/2021 that all five root CRLs were impacted, while issuing CRLs were not impacted. In response, GoDaddy discussed the need for a ceremony, then generated new root CRLs during a ceremony and deployed the updated CRLs to production on 10/01/2021. GoDaddy also reported mitigation steps including updating the scripts used to issue root CRLs, verifying OCSP responses, and updating the Starfield CP/CPS (version 4.14) published to https://certs.godaddy.com/repository. The bug was later closed as FIXED, with GoDaddy stating that all mitigation strategy items were completed and that it would continue to monitor for community questions or comments.
- GoDaddy and Starfield root CRLs were issued with a validity period of 365 days and 1 second.
- GoDaddy’s PKI Compliance reviewed Bug 1731164 and confirmed all five root CRLs were impacted.
- GoDaddy filed a related bug and decided to proceed with a ceremony to address the root CRL validity period issue.
- GoDaddy generated new root CRLs during a ceremony and deployed the updated root CRLs to production.
- GoDaddy published Starfield CP/CPS version 4.14 to update CRL/OCSP timeframe sections.
- GoDaddy — Opened an incident report describing the root CRL validity period issue, the discovery process, and the timeline of corrective actions.
- GoDaddy — Reported CP/CPS updates related to M4 were underway and targeted 10/22/2021 for publication.
- GoDaddy — Updated that CP/CPS changes had internal policy authority approval and should be deployed to the repository that week, targeting 10/22/2021 (or sooner) for publication.
- GoDaddy — Provided a summarized mitigation strategy and stated that mitigation items (including issuing updated root CRLs and publishing CP/CPS updates) were completed.
- GoDaddy — Confirmed all mitigation strategy items were completed and said the bug would be monitored for community questions/comments.
- GoDaddy — Requested closing the bug on 11/1/2021 and noted continued monitoring.
- Mozilla representative — Indicated closure would be scheduled on or about Friday, 30-Oct-2021.