← GoDaddy cases
Bugzilla #1904749 Certificate Misissuance

GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy identified a compliance issue related to CAA record checks after receiving a certificate problem report on June 23, 2024. The investigation revealed a software bug that allowed CAA validation to pass with incorrect record values that did not conform to RFC 8659. This misissuance affected 168 active certificates, prompting GoDaddy to revoke them on June 28, 2024, after deploying a fix on June 26. A full incident report was promised by July 5, 2024, and synthetic monitoring tests have since been implemented to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.85 11 comments
Chronology
  1. GoDaddy received a certificate problem report regarding CAA checks.
  2. GoDaddy deployed a fix for the CAA validation bug.
  3. GoDaddy revoked 168 active certificates affected by the issue.
  4. Synthetic monitoring for CAA records was deployed.
Thread Activity
  1. GoDaddy — GoDaddy reported a software bug in the CAA process that allowed incorrect validation.
  2. GoDaddy — GoDaddy confirmed that they did not stop issuance during the bug resolution process.
  3. GoDaddy — GoDaddy provided an update on the implementation of synthetic monitor tests.
  4. GoDaddy — GoDaddy confirmed that all action items related to the incident have been completed.
Participants
GoDaddy Tu-dresden representative Community commenter Mozilla representative
Similar Local Cases
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 91% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 87% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1904748 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 86% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
#1921254 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-09-26 · Closed 2025-02-19 · 77% similar
Izenpe: Duplicate attribute in Subject
#1896108 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-10 · Closed 2024-09-06 · 75% similar
Telia: Certificates Issued with lower case value in subject:countryName
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 75% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 74% similar
DigiCert: Random value in CNAME without underscore prefix
#1897346 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-05-17 · Closed 2024-07-24 · 74% similar
SECOM: Difference in upper and lower case between CN field and SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action