← GoDaddy cases
Bugzilla #1969296 Ca Certificate Compliance Certificate Misissuance Closure Request

GoDaddy: Certificates with invalid embedded SCT signatures

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported an incident involving two subscriber certificates that contained invalid embedded Signed Certificate Timestamp (SCT) signatures. The issue was identified on May 22, 2025, following a report received through certificate problem reporting. Both certificates were revoked by May 24, 2025. GoDaddy conducted an investigation and determined that the invalid SCTs were due to insufficient validation of SCT responses from a Certificate Transparency log. As a corrective measure, GoDaddy implemented a patch to verify SCTs before inclusion in final certificates and added monitoring for invalid SCT signatures. All action items related to the incident have been completed, and GoDaddy has requested closure of the case.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.90 12 comments
Chronology
  1. GoDaddy identifies invalid SCT signatures in two subscriber certificates.
  2. Both impacted certificates are revoked.
  3. GoDaddy submits closure report for the incident.
Thread Activity
  1. GoDaddy — Initial report of the incident regarding invalid SCT signatures.
  2. GoDaddy — Full incident report detailing the investigation and findings.
  3. GoDaddy — Closure report submitted, detailing remediation actions taken.
Participants
GoDaddy CCADB representative Community commenter Mm representative
External References
Similar Local Cases
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 100% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1904749 RESOLVED Certificate Misissuance Opened 2024-06-26 · Closed 2024-10-31 · 91% similar
GoDaddy : CAA checks passed when records contained incorrect variants of godaddy.com or starfieldtech.com
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 87% similar
Netlock: unspecifed revocation code (0) in CRL
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 87% similar
Financijska agencija (Fina): Mis-issued certificates
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 86% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 85% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 84% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 83% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action