← GoDaddy cases
Bugzilla #1777128 Certificate Misissuance

GoDaddy: Misissuance of Cross Signed Certs

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported that on 06/22/2022 it mis-issued two cross certificates (subordinate CA certificates) with not valid after dates of 06/22/2032. The certificates used generalizedTime encoding instead of UTCtime encoding, which GoDaddy stated violates Baseline Requirements section 7.1.2.4 and RFC 5280 4.1.2.5 regarding UTCTime encoding for validity dates through the year 2049. GoDaddy said the issue was identified after the production certificates were generated when crt.sh linters produced time encoding errors. In response, GoDaddy fixed the OpenSSL configuration/scripts used to generate the certificates to systematically use the correct time format, and stated the issue was isolated to these two certificates (subscriber certificates were not impacted). GoDaddy also deployed an updated CRL (sfroot-g2.crl) and verified the certificates were showing revoked, and reported that the two mis-issued certificates were revoked on 6/27/2022. The bug was marked RESOLVED with resolution FIXED, and GoDaddy later stated it completed updating and testing its ceremony process to prevent similar issues and that the bug could be closed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.90 6 comments
Chronology
  1. GoDaddy generated two cross certificates with generalizedTime encoding for the not-valid-after dates.
  2. GoDaddy revoked the two mis-issued cross certificates and updated the CRL to reflect revocation.
  3. Bug status was last changed to RESOLVED (FIXED).
Thread Activity
  1. GoDaddy — Opened the bug describing the misissuance, how it was discovered via crt.sh linter time encoding errors, the corrective actions taken (fixing generation scripts/configuration), and revocation/CRL updates; included crt.sh links for the affected certificates.
  2. Mozilla representative — Noted that Bug 1777270 was marked as a duplicate of this bug.
  3. GoDaddy — Said there were no formal updates and that GoDaddy would continue tracking for community questions.
  4. Mozilla representative — Reset the assignee because the bug assignee was inactive on Bugzilla.
  5. Mozilla representative — Indicated the bug would be closed on or about 12-Aug-2022 if there were no further questions.
  6. GoDaddy — Reported completion of updates and testing to the ceremony process to prevent similar issues and asked to close the bug.
Participants
GoDaddy Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1391429 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-08-17 · Closed 2024-02-27 · 82% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 79% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
#1330482 RESOLVED Certificate Misissuance Opened 2017-01-12 · Closed 2023-02-22 · 78% similar
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 77% similar
SwissSign: Certificate with key length 4098 bit
#1734114 RESOLVED Certificate Misissuance Opened 2021-10-05 · Closed 2024-05-09 · 74% similar
Netlock: Problem with NETLOCK's codesigning CA
#1774171 RESOLVED Certificate Misissuance Opened 2022-06-14 · Closed 2023-02-22 · 74% similar
Certigna: Precertificate with a validity period greater than 398-days
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 71% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1904748 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 70% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action