GoDaddy: Delayed revocation due to certificate problem reporting email being blocked/quarantined
This case reports delayed revocation by GoDaddy for certificates with compromised keys. The reporter said they reported multiple compromised certificates to GoDaddy’s certificate problem reporting email address after the Fortinet leak, but the certificates were still not revoked as of the time of the report. GoDaddy later explained that its problem-reporting email address (p**********s@starfieldtech.com) had malware/anti-virus scanning that blocked or quarantined emails containing certain attachment file types (specifically .key and .crt), which prevented GoDaddy from receiving the compromised key data in time. GoDaddy worked with the reporter to ensure it received the problematic keys and then revoked the affected certificates after retrieving quarantined emails and verifying the compromised keys. GoDaddy also updated the email malware configuration, added monitoring for blocked/quarantined problem reports, and introduced a web-based certificate problem reporting form. The bug is marked RESOLVED, and GoDaddy requested closure after completing the action items described in its incident report.
- GoDaddy’s certificate problem reporting email intake (p**********s@starfieldtech.com) was found to be blocking certain attachment file types used to report compromised keys.
- Bug 1942877 was filed reporting delayed revocation for multiple compromised-key certificates.
- GoDaddy confirmed it had revoked the affected certificates and emailed the reporter confirming revocation.
- GoDaddy reported rollout of a web-based problem reporting page for certificate problems.
- CCADB incident reporting requested final comments before the bug would be closed.
- Hboeck representative — Reported that certificates with compromised keys (from the Fortinet leak) were not yet revoked after attempts to submit them to GoDaddy’s problem reporting email, including a prior bug reference about the intake address not accepting attachments.
- GoDaddy — Apologized and stated emails were quarantined by GoDaddy’s email servers; said GoDaddy was working through revoking affected certificates and would draft a full report with action items.
- GoDaddy — Provided an incident report describing how malware filters blocked problem-report emails with certain attachment file types, the impact in days of delayed revocation, a timeline, root cause analysis, and lessons learned.
- GoDaddy — Shared an action-items update table, including completing email malware configuration updates, reviewing traffic history, adding monitoring, and introducing a webpage form solution (ongoing at that time).
- GoDaddy — Updated the webpage form action item due date to April 30, 2025 and stated continued monitoring of the practices@ email address until rollout.
- GoDaddy — Reported rollout of the web-based problem reporting page at https://sec.godaddy.com/report-certificate and requested closure after a closure summary.
- GoDaddy — Submitted the report closure summary stating remediation included updated email configuration, improved monitoring, and a web-based form, and requested bug closure.
- CCADB representative — Issued a final call for comments and noted the bug would be closed approximately 2025-05-08 if no further input was received.