← GoDaddy cases
Bugzilla #1742602
Certificate Problem Report
GoDaddy: Reported TLS Certificate Private Key Exposure
RESOLVED
DUPLICATE
GoDaddy
AI Summary
A reported exposure of private keys for a subset of GoDaddy customers raised concerns about potential compliance incidents. The issue was linked to an SEC filing indicating unauthorized access to a system containing end-entity private keys. Discussions among participants highlighted the need for clarity on whether this constituted an incident under the Baseline Requirements, particularly regarding timely revocation of affected certificates. Ultimately, the case was marked as a duplicate of another bug for further tracking and investigation.
Chronology
- SEC filing indicates private key exposure.
- Bug created to investigate potential incident.
- Bug marked as duplicate of bug 1742657.
Participants
Ryan Dickson
Brittany Randall
Matthias
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours
GoDaddy: Failure to revoke 210 subscriber certificates within 24 hours
GoDaddy: OV Documentation Reuse
GoDaddy: CRLs are version 1 and lack CRL Number extension
GoDaddy: CPR responses greater than 24 hours
GoDaddy: Revocation process is unusable due to contact address not accepting attachments
GoDaddy: Root CRLs exceed maximum validity period by 1 second
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold”