← GoDaddy cases
Bugzilla #1963456 Ca Certificate Compliance Certificate Misissuance Closure Request

GoDaddy: CA Certificates with HTTPS URL in AIA Field

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported an incident involving subordinate CA certificates that were issued with an HTTPS URL in the CA Certificate Authority Information Access (AIA) field, which violates the Baseline Requirements. The issue was identified on April 28, 2025, and the certificates were revoked by May 2, 2025. GoDaddy acknowledged the root causes as human error, misconfiguration of their Boulder tool, and a missing linter rule. They have since completed action items to improve their validation processes and are committed to enhancing their certificate issuance procedures.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.85 17 comments
Chronology
  1. Incident begins with the issuance of CA certificates containing HTTPS URLs in the AIA field.
  2. Non-compliance identified and reported via certificate problem reporting.
  3. Certificates revoked and updated CRLs published.
  4. Destruction ceremony of affected key material conducted.
  5. GoDaddy requests closure of the incident after completing all action items.
Thread Activity
  1. GoDaddy — Preliminary incident report submitted detailing the issue with HTTPS URLs in AIA field.
  2. GoDaddy — Full incident report provided with a detailed timeline and root cause analysis.
  3. GoDaddy — Closure summary submitted, confirming completion of all action items.
Participants
GoDaddy Community commenter Google representative CCADB representative Sectigo
External References
Similar Local Cases
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 100% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 94% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 88% similar
Financijska agencija (Fina): Mis-issued certificates
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 88% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 88% similar
Certigna: Subscriber certificate with EKU clientAuth only
#1904749 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 87% similar
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 87% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 85% similar
DigiCert: Several non-functioning AIA URLs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action