GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
GoDaddy reported that it issued 5,079 certificates whose embedded SCTs came from CT logs outside the logs’ stated temporal intervals. GoDaddy said its CT logic and the CT logs led to valid SCT signatures being embedded on certificates from incorrect temporal CT logs, and that affected certificates failed to meet Apple’s Certificate Transparency policy minimum SCT log entry requirements. The thread includes a timeline of when GoDaddy first issued precertificates with SCTs outside the stated temporal interval and when GoDaddy deployed patches to address the issue, including a production patch and a follow-up patch for an edge case involving timezone offsets. A commenter argued the bug should be closed as INVALID, stating there is no requirement to log to a CT log and that the certificates were logged to a log that violated the log’s stated policy rather than constituting a compliance violation for GoDaddy. Mozilla/CCADB marked the bug as INVALID, while GoDaddy continued to track action items such as ensuring CT log temporal intervals are respected and adding additional checks to SCT validation logic. GoDaddy later reported that the “Add additional check for temporal interval to SCT validation logic” action item was completed on 2025-07-28.
- GoDaddy began issuing precertificates with SCTs from CT logs outside the logs’ stated temporal intervals.
- GoDaddy deployed patches to address the CT temporal-interval issue, including an edge-case patch for timezone offsets.
- Mozilla/CCADB marked the bug as INVALID.
- GoDaddy completed the action item to add an additional check for temporal interval to SCT validation logic.
- GoDaddy — Opened with a preliminary incident report describing 5,079 precertificates incorrectly logged to DigiCert 2026h1 logs and stating an investigation was ongoing.
- GoDaddy — Posted a full incident report stating GoDaddy issued certificates with SCTs from CT logs outside stated temporal intervals and provided impact and a timeline.
- Community commenter — Requested closing as INVALID, arguing there is no requirement to log to a CT log and that the issue is the log should have rejected the request rather than a CA compliance violation.
- Mm representative — Agreed the bug should be closed as INVALID and noted the incident report helps raise awareness even if not required.
- GoDaddy — Agreed the bug may be invalid, continued monitoring, and listed action items and their statuses.
- CCADB representative — Marked the bug as INVALID and pointed to GoDaddy’s progress updates in the action items.
- GoDaddy — Reported that the action item to add an additional check for temporal interval to SCT validation logic was completed on 2025-07-28.