GoDaddy incident report on delayed revocation of subscriber certificates after Managed WordPress key exposure
GoDaddy reported that subscriber private keys in its Managed WordPress hosting environment were exposed after unauthorized third-party access was discovered on 2021-11-17 and confirmed on 2021-11-18. The case centered on GoDaddy’s failure to revoke impacted subscriber certificates within the Baseline Requirements timeframe after learning of the key exposure. GoDaddy first said about 310,000 certificates were not revoked within 5 days, then amended the incident summary to state that 457,911 subscriber certificates were not revoked within 24 hours of key compromise. GoDaddy said it reissued certificates before revoking them to minimize customer downtime, then later provided the full list of affected certificates and stated that all impacted certificates had been revoked. The company also said the Managed WordPress environment was physically and logically separate from the GoDaddy CA, and that the compromised credentials did not exist in the issuing CA or other PKI components. GoDaddy later reported that its internal after-action security review was completed and that all action plan items, including targeted consumer guidelines and increasing CA servers, were completed by 2022-03-30.
- Unauthorized third-party access was discovered in GoDaddy’s Managed WordPress hosting environment.
- GoDaddy confirmed that subscriber private keys associated with Managed WordPress customer accounts were exposed.
- GoDaddy disclosed that impacted subscriber certificates were not revoked within the required timeframe.
- GoDaddy stated that all 457,911 affected certificates had been revoked.
- GoDaddy said all incident action plan items had been completed.
- GoDaddy — GoDaddy filed a preliminary incident report saying about 310,000 subscriber certificates were not revoked within 5 days and that revocations would be completed within 72 hours.
- Community commenter — Ryan Sleevi asked whether the incident report would show that the 24-hour key-compromise revocation requirement did not apply and noted that the delay reasons needed objective support.
- GoDaddy — GoDaddy said all certificates associated with the incident, totaling 457,911, had been revoked and that the full incident report would follow.
- GoDaddy — GoDaddy posted the formal incident report, amended the issue summary to the 24-hour revocation requirement, and said the CA environment and PKI were not impacted.
- GoDaddy — GoDaddy said the internal after-action security review had been held in January 2022 and that remaining action items were targeted consumer guidelines and increasing CA servers.
- GoDaddy — GoDaddy said all action plan items were completed, including adding CA nodes, creating a node generation playbook, and formalizing targeted consumer guidelines.
- Mozilla representative — Mozilla asked whether there were any follow-up questions and said the bug could be closed if not.