← GoDaddy cases
Bugzilla #1793642
Certificate Problem Report
GoDaddy: CRLs are version 1 and lack CRL Number extension
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy reported an issue with their Certificate Revocation Lists (CRLs), which were found to be version 1 and lacking the required CRL Number extension, violating both their own Certificate Policy and RFC 5280. An internal review confirmed that six CRLs were impacted, with corrective actions initiated to generate compliant CRLs. A mock ceremony was conducted to address the issue, leading to the successful generation of updated CRLs by the end of November 2022. All remediation activities have since been completed.
Chronology
- Bug reported by Andrew Ayer detailing CRL issues.
- GoDaddy submitted an incident report outlining the problem and timeline of actions.
- Production ceremony held to generate updated CRLs.
- Updated CRLs verified and deployed.
Participants
Andrew Ayer
Brittany Randall
Chris Clements
External References
Similar Local Cases
GoDaddy: Failure to revoke 210 subscriber certificates within 24 hours
GoDaddy: Root CRLs exceed maximum validity period by 1 second
GoDaddy: OV Documentation Reuse
GoDaddy: CPR responses greater than 24 hours
GoDaddy: Revocation process is unusable due to contact address not accepting attachments
GoDaddy: Reported TLS Certificate Private Key Exposure
GoDaddy: Failure to Revoke Subscriber Certificates within 24 hours
NETLOCK: Disclosed CRL is expired