← GoDaddy cases
Bugzilla #1963456
Ca Certificate Compliance
Certificate Misissuance
Closure Request
GoDaddy: CA Certificates with HTTPS URL in AIA Field
RESOLVED
FIXED
GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GoDaddy reported an incident involving subordinate CA certificates that were issued with an HTTPS URL in the CA Certificate Authority Information Access (AIA) field, which violates the Baseline Requirements. The issue was identified on April 28, 2025, and the certificates were revoked by May 2, 2025. GoDaddy acknowledged the root causes as human error, misconfiguration of their Boulder tool, and a missing linter rule. They have since completed action items to improve their validation processes and are committed to enhancing their certificate issuance procedures.
Chronology
- Incident begins with the issuance of CA certificates containing HTTPS URLs in the AIA field.
- Non-compliance identified and reported via certificate problem reporting.
- Certificates revoked and updated CRLs published.
- Destruction ceremony of affected key material conducted.
- GoDaddy requests closure of the incident after completing all action items.
Thread Activity
- GoDaddy — Preliminary incident report submitted detailing the issue with HTTPS URLs in AIA field.
- GoDaddy — Full incident report provided with a detailed timeline and root cause analysis.
- GoDaddy — Closure summary submitted, confirming completion of all action items.
Participants
GoDaddy
Community commenter
Google representative
CCADB representative
Sectigo
External References
Similar Local Cases
GoDaddy: Certificates with invalid embedded SCT signatures
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
Financijska agencija (Fina): Mis-issued certificates
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
Certigna: Subscriber certificate with EKU clientAuth only
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
DigiCert: Several non-functioning AIA URLs