← GoDaddy cases
Bugzilla #1742602 Certificate Problem Report

GoDaddy: Reported TLS Certificate Private Key Exposure

RESOLVED (DUPLICATE) DUPLICATE GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This bug was opened based on an SEC filing and a related notification on MDSP describing a reported private key exposure affecting a subset of GoDaddy customers. The reporter asked for additional information to determine whether the described situation constituted a compliance incident under Mozilla’s Baseline Requirements, referencing the possibility of timely revocation requirements. GoDaddy’s assigned representative stated that they would provide a full incident report in a separate bug (1742657) and asked whether the current bug could be closed as a duplicate. The reporter agreed, and GoDaddy later marked this bug as a duplicate, directing readers to bug 1742657 for tracking. The discussion in the thread focused on whether the reported subscriber private key exposure should be treated as a CA incident and what would trigger incident reporting expectations. The bug is currently resolved as a duplicate of bug 1742657.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.86 10 comments
Chronology
  1. An SEC filing was published describing a reported private key exposure for a subset of GoDaddy customers.
  2. A Mozilla CA Program bug was filed to request information about whether the reported private key exposure constituted a compliance incident.
  3. The bug was marked as a duplicate and redirected to bug 1742657 for tracking.
Thread Activity
  1. Google representative — Filed the bug citing the SEC filing and MDSP notification, and asked for details to determine whether an incident occurred.
  2. Thisisntrocket representative — Asked for clarification on why the reporter considered it an incident and discussed potential Baseline Requirements revocation/CRL timing scenarios.
  3. Google representative — Explained that the filing suggested unauthorized access to a system storing end-entity private keys and referenced Chrome policy expectations for suspected/actual compliance incidents.
  4. GoDaddy — Said GoDaddy would provide a full incident report in bug 1742657 and asked if the current bug could be closed as a duplicate.
  5. Google representative — Agreed to close the bug as a duplicate.
  6. Thisisntrocket representative — Continued discussion about what qualifies as a CA incident versus a non-CA incident and asked where the reporting line should be.
  7. Google representative — Clarified that the concern was elevated due to a Baseline Requirements violation (4.9.1.1) and that the incident involved timely revocation of compromised keys.
  8. GoDaddy — Marked the bug as a duplicate and directed readers to bug 1742657 for tracking.
Participants
Google representative Thisisntrocket representative GoDaddy
Related Bugzilla IDs Mentioned
Similar Local Cases
#1037907 RESOLVED Policy Document Issue Opened 2014-07-12 · Closed 2022-11-14 · 45% similar
GoDaddy: Valid 1024 certificates
#708229 RESOLVED Common Ca Database Repository Issue Opened 2011-12-07 · Closed 2022-11-14 · 44% similar
GoDaddy's intermediate CA not in the Mozilla CA bundle
#1904748 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 44% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 44% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#1829024 RESOLVED Ca Certificate Compliance Opened 2023-04-19 · Closed 2023-05-05 · 43% similar
GoDaddy: CRL Issuer Mismatch
#1845803 RESOLVED Certificate Problem Report Opened 2023-07-27 · Closed 2023-09-08 · 41% similar
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold”
#1742657 RESOLVED Delayed Revocation Opened 2021-11-23 · Closed 2023-02-22 · 40% similar
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action