GoDaddy: CAA checks mishandled issuewild, allowing FQDN SANs to be added to wildcard certificates
On 2024-06-23, GoDaddy received a certificate problem report alerting it to potential concerns with its CAA checking. GoDaddy investigated and identified a software bug in its CAA validation process: certificates could be issued where the domain appeared in the 'issuewild' tag but not in the 'issue' tag, allowing the FQDN to be included as a SAN on a wildcard certificate. GoDaddy stated this violated CAB Baseline Requirements BR 3.2.2.8 and RFC 8659 section 4.3, which requires that each issuewild property be ignored when processing a request for an FQDN that is not a wildcard domain name. GoDaddy reported that it did not stop issuance during the period between bug confirmation and the code fix, and instead focused on the fix and customer rekeying. GoDaddy applied a code fix and later revoked 843 certificates on 2024-06-28 for the identified issue. The thread also includes follow-up on adding synthetic monitor tests to validate correct detection of CAA records that prevent issuance, with monitoring deployed and action items completed by early September 2024; the matter was set to be closed around 30-Oct-2024.
- GoDaddy received a certificate problem report about potential issues with its CAA checking implementation.
- GoDaddy deployed a code fix for the CAA validation bug.
- GoDaddy revoked 843 certificates identified as affected by the issue.
- Synthetic monitoring for CAA detection was deployed and operating as expected.
- GoDaddy — GoDaddy reported that a CPR led to discovery of a CAA validation bug involving 'issuewild' handling and stated it would publish a full incident report.
- Tu-dresden representative — The reporter said they observed and reported the bug alongside another related bug during CT log scanning and CAA record checking.
- GoDaddy — GoDaddy posted an incident report describing the RFC/BR violation, impact counts, and a timeline of investigation and remediation.
- Community commenter — A question was raised about whether GoDaddy stopped issuance despite the impact/timeline implying continued issuance.
- GoDaddy — GoDaddy answered that it did not stop issuance, stating the issue was extremely rare and describing its approach to fix, revocation, and customer rekeying.
- Mozilla representative — Mozilla requested an update on adding synthetic monitor tests to validate correct detection of CAA records that prevent issuance.
- GoDaddy — GoDaddy said synthetic monitor tests were being worked on, expected to roll out in early October, and that it would update after completion.
- GoDaddy — GoDaddy stated that as of 9/3/2024 synthetic monitoring was deployed and operating as expected, and all action items were completed.
- Mozilla representative — Mozilla indicated it would close the matter on or about 30-Oct-2024 if no further questions/comments appeared.