← GoDaddy cases
Bugzilla #1904749
Certificate Misissuance
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
RESOLVED
FIXED
GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GoDaddy identified a compliance issue related to CAA record checks after receiving a certificate problem report on June 23, 2024. The investigation revealed a software bug that allowed CAA validation to pass with incorrect record values that did not conform to RFC 8659. This misissuance affected 168 active certificates, prompting GoDaddy to revoke them on June 28, 2024, after deploying a fix on June 26. A full incident report was promised by July 5, 2024, and synthetic monitoring tests have since been implemented to prevent future occurrences.
Chronology
- GoDaddy received a certificate problem report regarding CAA checks.
- GoDaddy deployed a fix for the CAA validation bug.
- GoDaddy revoked 168 active certificates affected by the issue.
- Synthetic monitoring for CAA records was deployed.
Thread Activity
- GoDaddy — GoDaddy reported a software bug in the CAA process that allowed incorrect validation.
- GoDaddy — GoDaddy confirmed that they did not stop issuance during the bug resolution process.
- GoDaddy — GoDaddy provided an update on the implementation of synthetic monitor tests.
- GoDaddy — GoDaddy confirmed that all action items related to the incident have been completed.
Participants
GoDaddy
Tu-dresden representative
Community commenter
Mozilla representative
External References
Similar Local Cases
GoDaddy: Certificates with invalid embedded SCT signatures
GoDaddy: CA Certificates with HTTPS URL in AIA Field
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
Izenpe: Duplicate attribute in Subject
Telia: Certificates Issued with lower case value in subject:countryName
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
DigiCert: Random value in CNAME without underscore prefix
SECOM: Difference in upper and lower case between CN field and SAN