GoDaddy: CPR responses greater than 24 hours
GoDaddy reported that it failed to respond to two Certificate Problem Reports (CPRs) within 24 hours of receipt, which it stated is a violation of the Baseline Requirements (BRs) for Publicly Trusted SSL certificates (Section 4.9.5). The issue was discovered during a routine check of the CPR inbox on 09/27/2021, when an RA Associate identified two CPRs received on 09/26/2021 at 09:22 and 09:51 that were more than 24 hours old. GoDaddy stated that both CPRs reported a possible phishing attack related to the same certificate, and that the RA completed the CPR review process for both reports on 09/27/2021, including revocation of the reported certificate for eisbt.com. GoDaddy then escalated the incident to RA Management and communicated it to the Compliance team, held stakeholder meetings, and implemented changes to its internal process, including training and additional coverage between RA locations. It also stated that it implemented systematic alerts and reminders (including Slack callouts and escalations) and continued to track the bug for community questions. The bug was resolved as FIXED, and GoDaddy indicated mitigation items were completed and requested closure, which Mozilla planned to do unless objections were raised.
- Two Certificate Problem Reports were received reporting a possible phishing attack related to the same certificate.
- GoDaddy discovered the CPRs were older than 24 hours and completed review, including revocation of the reported certificate.
- GoDaddy implemented internal process changes and training to address the delay in CPR handling.
- GoDaddy implemented systematic alerts and reminders to prevent recurrence.
- GoDaddy — Opened an incident report stating GoDaddy failed to respond to two CPRs within 24 hours and provided a detailed timeline including revocation and process changes.
- GoDaddy — Confirmed all mitigation strategy items were completed and said GoDaddy would continue tracking the bug for community questions.
- GoDaddy — Requested closing the bug on 11/1/2021 while continuing to monitor for questions/comments.
- Mozilla representative — Indicated Mozilla would close the bug on or about Friday 30-Oct-2021 unless there were objections.