← GoDaddy cases
Bugzilla #1829024 Ca Certificate Compliance

GoDaddy: CRL Issuer Mismatch

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns a CRL issuer subject mismatch involving an unused intermediate certificate. GoDaddy reported that CRL Watch showed a CRL on an unused intermediate cert with an issuer subject mismatch with the public key, and that they were notified of the issuer mismatch by Ben Wilson on 04/04/2023. GoDaddy investigated the issue and updated the CRL in CCADB on 04/13/2023 to fix the problem. GoDaddy stated that no certificates were issued with the problem, and described the cause as the unused intermediate having the Root CRL re-listed on it, which was not caught when the standard changed to update blank CRLs to [""]. GoDaddy’s mitigation was to update CCADB to flag the intermediate as unused, and they indicated the implementation was completed on 04/13/2023. The bug was resolved as FIXED, and GoDaddy said they would continue monitoring the thread for questions but had no further updates.

Model: gpt-5.4-nano Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.84 6 comments
Chronology
  1. CRL Watch was checked and no GoDaddy CRLs were listed.
  2. GoDaddy was notified of an issuer mismatch observed via CRL Watch.
  3. GoDaddy investigated and updated the CRL in CCADB to fix the issuer mismatch.
  4. GoDaddy posted the Bugzilla report.
Thread Activity
  1. GoDaddy — Opened the report describing the CRL issuer mismatch on an unused intermediate, the timeline of actions, the statement that no certs were issued with the problem, and the mitigation to update CCADB to flag the intermediate as unused.
  2. Mozilla representative — Asked whether the incident should be flagged as "disclosure-failure" instead of "crl-failure".
  3. GoDaddy — Agreed that "disclosure-failure" would be more accurate.
  4. GoDaddy — Stated they would continue monitoring for questions but had resolved the issue and had no further updates.
  5. Mozilla representative — Said they would leave the bug open until Friday 5-5-2023 for additional comments or questions.
Participants
GoDaddy Mozilla representative
External References
Similar Local Cases
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 68% similar
KIR S.A.: Invalid organizationName
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 68% similar
KIR S.A.: Many certificates with OCSP Unknown
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2025-05-01 · 68% similar
HARICA: S/MIME certificate issuance without proper validation
#1647030 RESOLVED Ca Certificate Compliance Opened 2020-06-20 · Closed 2024-06-30 · 68% similar
GoDaddy: Agreed-Upon Website Domain Validation Method Issue
#1645832 RESOLVED Ca Certificate Compliance Opened 2020-06-15 · Closed 2023-02-22 · 67% similar
GoDaddy: Expired CRLs
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 67% similar
e-commerce monitoring GmbH: SCT in precertificate
#1918427 RESOLVED Ca Certificate Compliance Incident Closure Request Opened 2024-09-12 · Closed 2024-10-11 · 67% similar
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 66% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action