← GoDaddy cases
Bugzilla #1742657 Delayed Revocation

GoDaddy incident report on delayed revocation of subscriber certificates after Managed WordPress key exposure

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported that subscriber private keys in its Managed WordPress hosting environment were exposed after unauthorized third-party access was discovered on 2021-11-17 and confirmed on 2021-11-18. The case centered on GoDaddy’s failure to revoke impacted subscriber certificates within the Baseline Requirements timeframe after learning of the key exposure. GoDaddy first said about 310,000 certificates were not revoked within 5 days, then amended the incident summary to state that 457,911 subscriber certificates were not revoked within 24 hours of key compromise. GoDaddy said it reissued certificates before revoking them to minimize customer downtime, then later provided the full list of affected certificates and stated that all impacted certificates had been revoked. The company also said the Managed WordPress environment was physically and logically separate from the GoDaddy CA, and that the compromised credentials did not exist in the issuing CA or other PKI components. GoDaddy later reported that its internal after-action security review was completed and that all action plan items, including targeted consumer guidelines and increasing CA servers, were completed by 2022-03-30.

Model: gpt-5.4-mini Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.98 44 comments
Chronology
  1. Unauthorized third-party access was discovered in GoDaddy’s Managed WordPress hosting environment.
  2. GoDaddy confirmed that subscriber private keys associated with Managed WordPress customer accounts were exposed.
  3. GoDaddy disclosed that impacted subscriber certificates were not revoked within the required timeframe.
  4. GoDaddy stated that all 457,911 affected certificates had been revoked.
  5. GoDaddy said all incident action plan items had been completed.
Thread Activity
  1. GoDaddy — GoDaddy filed a preliminary incident report saying about 310,000 subscriber certificates were not revoked within 5 days and that revocations would be completed within 72 hours.
  2. Community commenter — Ryan Sleevi asked whether the incident report would show that the 24-hour key-compromise revocation requirement did not apply and noted that the delay reasons needed objective support.
  3. GoDaddy — GoDaddy said all certificates associated with the incident, totaling 457,911, had been revoked and that the full incident report would follow.
  4. GoDaddy — GoDaddy posted the formal incident report, amended the issue summary to the 24-hour revocation requirement, and said the CA environment and PKI were not impacted.
  5. GoDaddy — GoDaddy said the internal after-action security review had been held in January 2022 and that remaining action items were targeted consumer guidelines and increasing CA servers.
  6. GoDaddy — GoDaddy said all action plan items were completed, including adding CA nodes, creating a node generation playbook, and formalizing targeted consumer guidelines.
  7. Mozilla representative — Mozilla asked whether there were any follow-up questions and said the bug could be closed if not.
Participants
GoDaddy Community commenter Google representative Sectigo DigiCert Internet Security Research Group Victorymedium representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1640310 RESOLVED Delayed Revocation Opened 2020-05-22 · Closed 2023-02-22 · 97% similar
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
#1793848 RESOLVED Delayed Revocation Opened 2022-10-05 · Closed 2023-02-22 · 97% similar
GoDaddy: Failure to revoke 210 subscriber certificates within 24 hours
#1639798 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 96% similar
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
#1734953 RESOLVED Delayed Revocation Opened 2021-10-08 · Closed 2024-06-30 · 96% similar
GoDaddy: CPR responses greater than 24 hours
#1902868 RESOLVED Delayed Revocation Opened 2024-06-15 · Closed 2024-08-21 · 96% similar
GoDaddy: CPR was not responded to in 24 hours
#1949895 RESOLVED Delayed Revocation Closure Request Opened 2025-02-21 · Closed 2025-05-13 · 89% similar
GoDaddy: Delayed CRL File Updates
#1942877 RESOLVED Delayed Revocation Opened 2025-01-21 · Closed 2025-07-16 · 88% similar
GoDaddy: Delayed revocation
#1524815 RESOLVED Delayed Revocation Opened 2019-02-03 · Closed 2023-02-22 · 87% similar
GoDaddy: failure to revoke underscores

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action