← GoDaddy cases
Bugzilla #1970259 Certificate Misissuance Incident Self Reported Incident

GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs

RESOLVED INVALID GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GoDaddy reported that it issued 5,079 certificates whose embedded SCTs came from CT logs outside the logs’ stated temporal intervals. GoDaddy said its CT logic and the CT logs led to valid SCT signatures being embedded on certificates from incorrect temporal CT logs, and that affected certificates failed to meet Apple’s Certificate Transparency policy minimum SCT log entry requirements. The thread includes a timeline of when GoDaddy first issued precertificates with SCTs outside the stated temporal interval and when GoDaddy deployed patches to address the issue, including a production patch and a follow-up patch for an edge case involving timezone offsets. A commenter argued the bug should be closed as INVALID, stating there is no requirement to log to a CT log and that the certificates were logged to a log that violated the log’s stated policy rather than constituting a compliance violation for GoDaddy. Mozilla/CCADB marked the bug as INVALID, while GoDaddy continued to track action items such as ensuring CT log temporal intervals are respected and adding additional checks to SCT validation logic. GoDaddy later reported that the “Add additional check for temporal interval to SCT validation logic” action item was completed on 2025-07-28.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-28 19:25 UTC Confidence: 0.52 9 comments
Chronology
  1. GoDaddy began issuing precertificates with SCTs from CT logs outside the logs’ stated temporal intervals.
  2. GoDaddy deployed patches to address the CT temporal-interval issue, including an edge-case patch for timezone offsets.
  3. Mozilla/CCADB marked the bug as INVALID.
  4. GoDaddy completed the action item to add an additional check for temporal interval to SCT validation logic.
Thread Activity
  1. GoDaddy — Opened with a preliminary incident report describing 5,079 precertificates incorrectly logged to DigiCert 2026h1 logs and stating an investigation was ongoing.
  2. GoDaddy — Posted a full incident report stating GoDaddy issued certificates with SCTs from CT logs outside stated temporal intervals and provided impact and a timeline.
  3. Community commenter — Requested closing as INVALID, arguing there is no requirement to log to a CT log and that the issue is the log should have rejected the request rather than a CA compliance violation.
  4. Mm representative — Agreed the bug should be closed as INVALID and noted the incident report helps raise awareness even if not required.
  5. GoDaddy — Agreed the bug may be invalid, continued monitoring, and listed action items and their statuses.
  6. CCADB representative — Marked the bug as INVALID and pointed to GoDaddy’s progress updates in the action items.
  7. GoDaddy — Reported that the action item to add an additional check for temporal interval to SCT validation logic was completed on 2025-07-28.
Participants
GoDaddy Community commenter Mm representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2032473 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-04-16 Still Open · 78% similar
CCA India: Misissuance detected by PKIMetal
#2044023 RESOLVED Certificate Misissuance Self Reported Incident Remediation Tracking Opened By Ca Opened 2026-06-01 · Closed 2026-07-02 · 78% similar
Asseco DS / Certum: Cross-Certificates subject encoding discrepancy
#1825232 RESOLVED Certificate Misissuance Self Reported Incident Opened 2023-03-29 · Closed 2023-03-31 · 78% similar
SwissSign: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 76% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#2037000 ASSIGNED Self Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-05-05 Still Open · 76% similar
D-Trust: Missing Pre-Sign Linting for S/MIME Issuing CAs
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 75% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 74% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 72% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action