GoDaddy: Reported TLS Certificate Private Key Exposure
This bug was opened based on an SEC filing and a related notification on MDSP describing a reported private key exposure affecting a subset of GoDaddy customers. The reporter asked for additional information to determine whether the described situation constituted a compliance incident under Mozilla’s Baseline Requirements, referencing the possibility of timely revocation requirements. GoDaddy’s assigned representative stated that they would provide a full incident report in a separate bug (1742657) and asked whether the current bug could be closed as a duplicate. The reporter agreed, and GoDaddy later marked this bug as a duplicate, directing readers to bug 1742657 for tracking. The discussion in the thread focused on whether the reported subscriber private key exposure should be treated as a CA incident and what would trigger incident reporting expectations. The bug is currently resolved as a duplicate of bug 1742657.
- An SEC filing was published describing a reported private key exposure for a subset of GoDaddy customers.
- A Mozilla CA Program bug was filed to request information about whether the reported private key exposure constituted a compliance incident.
- The bug was marked as a duplicate and redirected to bug 1742657 for tracking.
- Google representative — Filed the bug citing the SEC filing and MDSP notification, and asked for details to determine whether an incident occurred.
- Thisisntrocket representative — Asked for clarification on why the reporter considered it an incident and discussed potential Baseline Requirements revocation/CRL timing scenarios.
- Google representative — Explained that the filing suggested unauthorized access to a system storing end-entity private keys and referenced Chrome policy expectations for suspected/actual compliance incidents.
- GoDaddy — Said GoDaddy would provide a full incident report in bug 1742657 and asked if the current bug could be closed as a duplicate.
- Google representative — Agreed to close the bug as a duplicate.
- Thisisntrocket representative — Continued discussion about what qualifies as a CA incident versus a non-CA incident and asked where the reporting line should be.
- Google representative — Clarified that the concern was elevated due to a Baseline Requirements violation (4.9.1.1) and that the incident involved timely revocation of compromised keys.
- GoDaddy — Marked the bug as a duplicate and directed readers to bug 1742657 for tracking.