GoDaddy: Edge Case for Data Reuse Outside of Timeframes
GoDaddy reported a compliance incident discovered during a recent 3% audit on 2024-07-22, where a DV UCC certificate was found to have used two prior completed domain validations older than 398 days at the time of issuance, violating CAB Baseline Requirements Section 4.2.1. GoDaddy revoked the reported mis-issued certificate on 2024-07-23 within the 24-hour timeframe specified in CAB 4.9.1.1, and then investigated the cause. The investigation identified a code bug in the pre-issuance logic that checks whether domains designated as able to use prior domain validation at request time can still use that validation at issuance time. After identifying the edge case, GoDaddy surfaced and revoked 10 additional impacted active certificates within the required 24-hour window (revocations noted as completed on 2024-07-25). GoDaddy deployed a fix to production on 2024-07-25 06:43:00 UTC and reported that there have been no additional issues since the fix was deployed. In a later update, GoDaddy stated that synthetic monitoring was deployed and operating as expected, and that all action items related to the incident were completed; Mozilla indicated it would close the matter around 30-Oct-2024.
- GoDaddy’s 3% audit identified a DV UCC certificate using prior domain validations older than 398 days at issuance.
- GoDaddy revoked the initially identified mis-issued certificate within the CAB-specified 24-hour window.
- GoDaddy deployed a fix to production and revoked 10 additional impacted active certificates.
- GoDaddy deployed synthetic monitoring for the incident and reported it operating as expected.
- GoDaddy — GoDaddy submitted a preliminary incident report describing the audit finding, the CAB 4.2.1 violation, revocation of the reported certificate, and that a code bug was found and a fix would be published.
- GoDaddy — GoDaddy published the incident report with details on the mis-issued certificate, the identified code bug, the impact (including additional surfaced certificates), and the revocation and fix timeline.
- GoDaddy — GoDaddy reported that synthetic monitoring was deployed and operating as expected and that all action items related to the incident were completed.
- Mozilla representative — Mozilla stated there were no questions or comments and that it would close the matter on or about 30-Oct-2024.