← DigiCert cases
Bugzilla #1970259 · Certificate Problem Report
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
DigiCert · RESOLVED
AI Summary
GoDaddy reported an incident involving 5079 precertificates that were incorrectly logged to DigiCert SCT logs, violating Apple's Certificate Transparency policy. The issue stemmed from bugs in GoDaddy's CT logic and the CT logs, leading to valid SCT signatures being embedded from incorrect temporal logs. Although the incident was resolved and marked as invalid, it raised awareness about the importance of compliance with SCT log requirements.
Chronology
- Non-compliance identified
- GoDaddy deployed a patch to address the issue
- Additional checks for SCT validation logic completed
Participants
Steven Deitte
External References
Similar Local Cases
DigiCert: Incorrect CP listed in CCADB
DigiCert: Invalid localityName
DigiCert: Apple: Non-compliant Common Name Length
DigiCert: Failure to revoke key-compromised certificate
DigiCert: Issuance of Cert with Compromised Key
DigiCert: Failure to properly encode Subject name
DigiCert: Apple: Precertificates without corresponding certificates return OCSP value of "unknown"
DigiCert: IP in dnsName