← GoDaddy cases
Bugzilla #1904748 Certificate Misissuance

GoDaddy: CAA checks mishandled issuewild, allowing FQDN SANs to be added to wildcard certificates

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On 2024-06-23, GoDaddy received a certificate problem report alerting it to potential concerns with its CAA checking. GoDaddy investigated and identified a software bug in its CAA validation process: certificates could be issued where the domain appeared in the 'issuewild' tag but not in the 'issue' tag, allowing the FQDN to be included as a SAN on a wildcard certificate. GoDaddy stated this violated CAB Baseline Requirements BR 3.2.2.8 and RFC 8659 section 4.3, which requires that each issuewild property be ignored when processing a request for an FQDN that is not a wildcard domain name. GoDaddy reported that it did not stop issuance during the period between bug confirmation and the code fix, and instead focused on the fix and customer rekeying. GoDaddy applied a code fix and later revoked 843 certificates on 2024-06-28 for the identified issue. The thread also includes follow-up on adding synthetic monitor tests to validate correct detection of CAA records that prevent issuance, with monitoring deployed and action items completed by early September 2024; the matter was set to be closed around 30-Oct-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.86 10 comments
Chronology
  1. GoDaddy received a certificate problem report about potential issues with its CAA checking implementation.
  2. GoDaddy deployed a code fix for the CAA validation bug.
  3. GoDaddy revoked 843 certificates identified as affected by the issue.
  4. Synthetic monitoring for CAA detection was deployed and operating as expected.
Thread Activity
  1. GoDaddy — GoDaddy reported that a CPR led to discovery of a CAA validation bug involving 'issuewild' handling and stated it would publish a full incident report.
  2. Tu-dresden representative — The reporter said they observed and reported the bug alongside another related bug during CT log scanning and CAA record checking.
  3. GoDaddy — GoDaddy posted an incident report describing the RFC/BR violation, impact counts, and a timeline of investigation and remediation.
  4. Community commenter — A question was raised about whether GoDaddy stopped issuance despite the impact/timeline implying continued issuance.
  5. GoDaddy — GoDaddy answered that it did not stop issuance, stating the issue was extremely rare and describing its approach to fix, revocation, and customer rekeying.
  6. Mozilla representative — Mozilla requested an update on adding synthetic monitor tests to validate correct detection of CAA records that prevent issuance.
  7. GoDaddy — GoDaddy said synthetic monitor tests were being worked on, expected to roll out in early October, and that it would update after completion.
  8. GoDaddy — GoDaddy stated that as of 9/3/2024 synthetic monitoring was deployed and operating as expected, and all action items were completed.
  9. Mozilla representative — Mozilla indicated it would close the matter on or about 30-Oct-2024 if no further questions/comments appeared.
Participants
GoDaddy Tu-dresden representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1904749 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 86% similar
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
#1970259 RESOLVED Certificate Misissuance Incident Self Reported Incident Opened 2025-06-03 · Closed 2025-08-26 · 80% similar
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
#1943379 RESOLVED Certificate Misissuance Opened 2025-01-23 · Closed 2025-05-08 · 77% similar
Actalis: CRL with duplicate serial number in revokedCertificates
#1809864 RESOLVED Certificate Misissuance Opened 2023-01-12 · Closed 2024-05-09 · 70% similar
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
#1777128 RESOLVED Certificate Misissuance Opened 2022-06-28 · Closed 2023-02-22 · 70% similar
GoDaddy: Misissuance of Cross Signed Certs
#2041774 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-05-22 Still Open · 69% similar
OATI: AIA CA Issuer field pointing to PEM encoded cert
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 69% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 69% similar
GoDaddy: Certificates with invalid embedded SCT signatures

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action