← GoDaddy cases
Bugzilla #1793642 Policy Document Issue

GoDaddy: CRLs are version 1 and lack CRL Number extension

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy disclosed a compliance issue regarding its Certificate Revocation Lists (CRLs), which were found to be version 1 and lacking the required CRL Number extension, violating both their own Certificate Policy and RFC 5280. The issue was reported by Andrew Ayer on October 4, 2022. GoDaddy's internal teams confirmed the problem and initiated a review process. An incident report was created, detailing the timeline of events and the steps taken to address the issue. The production ceremony to generate updated CRLs was successfully completed on November 28, 2022, and the new CRLs were published on November 29, 2022, resolving the compliance issue.

Model: gpt-4o-mini Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.90 11 comments
Chronology
  1. GoDaddy disclosed a compliance issue with its CRLs.
  2. GoDaddy generated updated root CRLs under ceremony.
  3. GoDaddy verified that the updated CRLs were deployed.
Thread Activity
  1. Mm representative — Created a bug report detailing the CRL version and extension issue.
  2. GoDaddy — Acknowledged the issue and stated that an internal review would take place.
  3. GoDaddy — Provided an incident report summarizing the problem and actions taken.
  4. GoDaddy — Reported that the production ceremony for updated CRLs was completed.
Participants
Community commenter
External References
Similar Local Cases
#1705904 RESOLVED Policy Document Issue Self Reported Incident Opened 2021-04-17 · Closed 2023-02-22 · 69% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 63% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#2004492 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-12-05 · Closed 2026-02-05 · 61% similar
IdenTrust: CA Certificate not published in DER Encoded Format
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 61% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1948600 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-02-17 · Closed 2025-07-01 · 61% similar
IZENPE: Outdated CPS for Izenpe Root
#1836694 RESOLVED Certificate Misissuance Policy Document Issue Opened 2023-06-05 · Closed 2023-09-29 · 61% similar
Hongkong Post: Invalid EV cert businessCategory
#1688382 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-23 · Closed 2023-02-22 · 60% similar
Camerfirma: No disclosure of verification sources
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 60% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action