← GoDaddy cases
Bugzilla #1759959
Self Incident Disclosure
GoDaddy: OV Documentation Reuse
RESOLVED
FIXED
GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GoDaddy disclosed a compliance issue involving the issuance of 36 Organization Validated (OV) certificates that reused documentation older than the allowed 825 days, violating CA/B Forum Baseline Requirements. The issue was identified during a 3% certificate audit on March 8, 2022, when a bug in the code was discovered that allowed this reuse. GoDaddy revoked all impacted certificates by March 9, 2022, and updated their application configuration to prevent future occurrences. The CA has since completed a code fix and validation linter review to enhance compliance checks.
Chronology
- GoDaddy's RA team identifies a compliance issue during a 3% certificate audit.
- All impacted certificates are revoked.
- GoDaddy deploys a fix and re-enables documentation reuse.
Thread Activity
- GoDaddy — GoDaddy acknowledges the compliance issue and outlines the timeline of actions taken.
- GoDaddy — GoDaddy provides an update on the incident report and additional impacted certificates.
- GoDaddy — GoDaddy confirms completion of all action items related to the compliance issue.
- Mozilla representative — Mozilla closes the bug as complete.
Participants
GoDaddy
Community commenter
Mozilla representative
External References
Similar Local Cases
GoDaddy: Issued EV Wildcard Certificate
GoDaddy: Expired CRLs
GoDaddy: Root CRLs exceed maximum validity period by 1 second
GoDaddy: Edge Case for Data Reuse Outside of Timeframes
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
GoDaddy: Domain Validation Reuse Issue
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
GoDaddy: Random Value Vulnerability in Domain Validation Method