← GoDaddy cases
Bugzilla #1905419 Ca Security Vulnerability

GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported an issue with their OCSP response mechanism, which intermittently returned 'unauthorized' responses for newly issued certificates. This problem arose due to latency in the OCSP response propagation process as GoDaddy scaled up its certificate issuance. The CA acknowledged the issue and committed to improvements, including adjusting the response syncing schedules and implementing a fast-track propagation script. A detailed report on the incident was promised once the short-term improvements were deployed. The issue has since been resolved, and the necessary actions have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.85 11 comments
Chronology
  1. CPR sent to GoDaddy regarding unauthorized OCSP response
  2. Fast-track propagation script added to improve OCSP response times
Thread Activity
  1. Community commenter — Noticed OCSP status is unavailable for freshly minted certificates on GoDaddy.
  2. GoDaddy — Provided preliminary response regarding latency in OCSP batching process.
  3. GoDaddy — Summarized the OCSP response sync mechanism degradation and actions taken.
  4. Mozilla representative — Indicated that all action items related to this incident have been completed.
Participants
Community commenter GoDaddy Mozilla representative Mm representative
External References
Similar Local Cases
#1793445 RESOLVED Ca Security Vulnerability Remediation Tracking Opened 2022-10-03 · Closed 2023-04-19 · 77% similar
TWCA: "unknown" OCSP response for issued certificates
#1793467 RESOLVED Ca Security Vulnerability Opened 2022-10-03 · Closed 2023-02-22 · 76% similar
Google Trust Services: invalid CRL reason code
#1622505 RESOLVED Ca Security Vulnerability Opened 2020-03-14 · Closed 2023-02-22 · 70% similar
GlobalSign: OCSP Status HTTP 530
#1773556 RESOLVED Ca Security Vulnerability Opened 2022-06-09 · Closed 2023-02-22 · 69% similar
Google Trust Services: Incorrect OCSP responses for certain certificates
#1904749 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 69% similar
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 67% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 67% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1838315 RESOLVED Ca Security Vulnerability Incident Opened 2023-06-13 · Closed 2023-10-12 · 67% similar
IdenTrust: Certificate with missing details flagged by OCSP Watch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action