← GoDaddy cases
Bugzilla #1909948 Incident

GoDaddy: Edge Case for Data Reuse Outside of Timeframes

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported a compliance incident discovered during a recent 3% audit on 2024-07-22, where a DV UCC certificate was found to have used two prior completed domain validations older than 398 days at the time of issuance, violating CAB Baseline Requirements Section 4.2.1. GoDaddy revoked the reported mis-issued certificate on 2024-07-23 within the 24-hour timeframe specified in CAB 4.9.1.1, and then investigated the cause. The investigation identified a code bug in the pre-issuance logic that checks whether domains designated as able to use prior domain validation at request time can still use that validation at issuance time. After identifying the edge case, GoDaddy surfaced and revoked 10 additional impacted active certificates within the required 24-hour window (revocations noted as completed on 2024-07-25). GoDaddy deployed a fix to production on 2024-07-25 06:43:00 UTC and reported that there have been no additional issues since the fix was deployed. In a later update, GoDaddy stated that synthetic monitoring was deployed and operating as expected, and that all action items related to the incident were completed; Mozilla indicated it would close the matter around 30-Oct-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.90 4 comments
Chronology
  1. GoDaddy’s 3% audit identified a DV UCC certificate using prior domain validations older than 398 days at issuance.
  2. GoDaddy revoked the initially identified mis-issued certificate within the CAB-specified 24-hour window.
  3. GoDaddy deployed a fix to production and revoked 10 additional impacted active certificates.
  4. GoDaddy deployed synthetic monitoring for the incident and reported it operating as expected.
Thread Activity
  1. GoDaddy — GoDaddy submitted a preliminary incident report describing the audit finding, the CAB 4.2.1 violation, revocation of the reported certificate, and that a code bug was found and a fix would be published.
  2. GoDaddy — GoDaddy published the incident report with details on the mis-issued certificate, the identified code bug, the impact (including additional surfaced certificates), and the revocation and fix timeline.
  3. GoDaddy — GoDaddy reported that synthetic monitoring was deployed and operating as expected and that all action items related to the incident were completed.
  4. Mozilla representative — Mozilla stated there were no questions or comments and that it would close the matter on or about 30-Oct-2024.
Participants
GoDaddy Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1924992 RESOLVED Incident Opened 2024-10-16 · Closed 2025-04-03 · 85% similar
GoDaddy: Does not provide a method for domain owners to revoke their certificates
#1533774 RESOLVED Incident Opened 2019-03-08 · Closed 2023-02-22 · 79% similar
GoDaddy: Insufficient serial number entropy
#1942241 RESOLVED Incident Opened 2025-01-17 · Closed 2025-05-13 · 77% similar
GoDaddy: Revocation process is unusable due to contact address not accepting attachments
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 71% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 70% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 70% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1905446 RESOLVED Incident Opened 2024-06-28 · Closed 2024-12-09 · 70% similar
IdenTrust: Unauthorized OCSP response on a Timestamp certificate
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 70% similar
Izenpe: certificate issued to internal domain

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action