← GoDaddy cases
Bugzilla #1904749 Certificate Problem Report

GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com

RESOLVED FIXED GoDaddy
AI Summary

GoDaddy identified a software bug in its CAA checking process that allowed certificate issuance when CAA records contained incorrect variants of 'godaddy.com' or 'starfieldtech.com'. This non-conformance with RFC 8659 violated the Baseline Requirements for certificate issuance. The issue was reported on June 23, 2024, and a fix was deployed on June 26, 2024. GoDaddy subsequently revoked 168 active certificates that were affected by this issue. A full incident report was promised by July 5, 2024.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Confidence: 0.90
Chronology
  1. GoDaddy received a certificate problem report regarding CAA checks.
  2. GoDaddy deployed a fix for the identified bug.
  3. GoDaddy revoked 168 active certificates affected by the issue.
  4. GoDaddy promised to publish a full incident report.
Participants
star@godaddy.com pouyan.tehrani@tu-dresden.de rdaurne77@gmail.com bwilson@mozilla.com
Similar Local Cases
#1904748 RESOLVED Certificate Problem Report Opened 2024-06-26 · Closed 2024-10-31 · 81% similar
GoDaddy : CAA checks did not properly handle issuewild tag allowing FQDN SANs to be added to wildcard certs
#1905419 RESOLVED Certificate Problem Report Opened 2024-06-28 · Closed 2024-10-31 · 72% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#1605804 RESOLVED Certificate Problem Report Opened 2019-12-24 · Closed 2023-02-22 · 58% similar
GoDaddy: Domain Validation Reuse Issue
#1829024 RESOLVED Certificate Problem Report Opened 2023-04-19 · Closed 2023-05-05 · 58% similar
GoDaddy: CRL Issuer Mismatch
#1897630 RESOLVED Certificate Problem Report Opened 2024-05-19 · Closed 2024-08-15 · 57% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1924992 RESOLVED Certificate Problem Report Opened 2024-10-16 · Closed 2025-04-03 · 56% similar
GoDaddy: Does not provide a method for domain owners to revoke their certificates
#1886788 RESOLVED Certificate Problem Report Opened 2024-03-21 · Closed 2024-06-01 · 56% similar
ACCV: Delayed revocation of TLS certificates affected by bug #1884532
#2034251 RESOLVED Certificate Problem Report Opened 2026-04-22 · Closed 2026-05-13 · 55% similar
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action