← GoDaddy cases
Bugzilla #1759959
Certificate Problem Report
GoDaddy: OV Documentation Reuse
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy identified a compliance issue involving 36 Organization Validated (OV) certificates that reused documentation older than the allowed 825 days, violating the Baseline Requirements. The issue was discovered during a 3% certificate audit, leading to the revocation of all impacted certificates. GoDaddy promptly updated their application configuration to prevent the reuse of outdated documentation and has since completed a code fix to address the underlying bug. All action items related to this incident have been completed, ensuring compliance moving forward.
Chronology
- PKI development confirms a bug allowing reuse of outdated OV documentation.
- All impacted certificates are revoked.
- Code fix deployed, documentation reuse re-enabled.
Participants
Brittany Randall
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours
GlobalSign: Empty SingleExtension in OCSP responses
GoDaddy: Root CRLs exceed maximum validity period by 1 second
GoDaddy: CRLs are version 1 and lack CRL Number extension
GoDaddy: Document Reuse Issue
GoDaddy: Agreed-Upon Website Domain Validation Method Issue
Entrust: Printable String Constraint Failure