← GoDaddy cases
Bugzilla #1969296
Certificate Problem Report
GoDaddy: Certificates with invalid embedded SCT signatures
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy reported an incident involving two subscriber certificates that contained invalid embedded Signed Certificate Timestamp (SCT) signatures. Both certificates were revoked on May 24, 2025, after the issue was identified on May 22, 2025. The root cause was traced to an invalid SCT returned by the CT log provider, compounded by insufficient validation processes at GoDaddy. Remediation steps included revoking the impacted certificates and implementing additional validation logic for SCT signatures.
Chronology
- Non-compliance incident begins
- Incident identified
- Certificates revoked
- Closure report submitted
Participants
Steven Deitte
External References
Similar Local Cases
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
GoDaddy: CA Certificates Published in PEM format
GoDaddy: CA Certificates with HTTPS URL in AIA Field
GoDaddy: Partitioned CRL files missing Issuing Distribution Point
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB
GoDaddy: Delayed revocation
GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates
GoDaddy: Delayed CRL File Updates