GoDaddy: Certificates with invalid embedded SCT signatures
GoDaddy reported an incident involving two subscriber certificates that contained invalid embedded Signed Certificate Timestamp (SCT) signatures. The issue was identified on May 22, 2025, following a report received through certificate problem reporting. Both certificates were revoked by May 24, 2025. GoDaddy conducted an investigation and determined that the invalid SCTs were due to insufficient validation of SCT responses from a Certificate Transparency log. As a corrective measure, GoDaddy implemented a patch to verify SCTs before inclusion in final certificates and added monitoring for invalid SCT signatures. All action items related to the incident have been completed, and GoDaddy has requested closure of the case.
- GoDaddy identifies invalid SCT signatures in two subscriber certificates.
- Both impacted certificates are revoked.
- GoDaddy submits closure report for the incident.
- GoDaddy — Initial report of the incident regarding invalid SCT signatures.
- GoDaddy — Full incident report detailing the investigation and findings.
- GoDaddy — Closure report submitted, detailing remediation actions taken.