GoDaddy: CRL Issuer Mismatch
The case concerns a CRL issuer subject mismatch involving an unused intermediate certificate. GoDaddy reported that CRL Watch showed a CRL on an unused intermediate cert with an issuer subject mismatch with the public key, and that they were notified of the issuer mismatch by Ben Wilson on 04/04/2023. GoDaddy investigated the issue and updated the CRL in CCADB on 04/13/2023 to fix the problem. GoDaddy stated that no certificates were issued with the problem, and described the cause as the unused intermediate having the Root CRL re-listed on it, which was not caught when the standard changed to update blank CRLs to [""]. GoDaddy’s mitigation was to update CCADB to flag the intermediate as unused, and they indicated the implementation was completed on 04/13/2023. The bug was resolved as FIXED, and GoDaddy said they would continue monitoring the thread for questions but had no further updates.
- CRL Watch was checked and no GoDaddy CRLs were listed.
- GoDaddy was notified of an issuer mismatch observed via CRL Watch.
- GoDaddy investigated and updated the CRL in CCADB to fix the issuer mismatch.
- GoDaddy posted the Bugzilla report.
- GoDaddy — Opened the report describing the CRL issuer mismatch on an unused intermediate, the timeline of actions, the statement that no certs were issued with the problem, and the mitigation to update CCADB to flag the intermediate as unused.
- Mozilla representative — Asked whether the incident should be flagged as "disclosure-failure" instead of "crl-failure".
- GoDaddy — Agreed that "disclosure-failure" would be more accurate.
- GoDaddy — Stated they would continue monitoring for questions but had resolved the issue and had no further updates.
- Mozilla representative — Said they would leave the bug open until Friday 5-5-2023 for additional comments or questions.