← GoDaddy cases
Bugzilla #1970259
Certificate Problem Report
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
RESOLVED
INVALID
GoDaddy
AI Summary
GoDaddy reported an incident involving 5079 precertificates that were incorrectly logged to DigiCert SCT logs, violating Apple's Certificate Transparency policy. The issue stemmed from bugs in GoDaddy's CT logic and the CT logs, resulting in valid SCT signatures being embedded on certificates from incorrect temporal CT logs. Although the affected certificates did not meet the minimum SCT log entry requirements, they were still BR-compliant. The case was ultimately marked as invalid, with no compliance violation found.
Chronology
- Non-compliance identified
- GoDaddy deployed patches to address the issue
- Additional checks for SCT validation logic completed
Participants
Steven Deitte
External References
Similar Local Cases
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
GoDaddy: Certificates with invalid embedded SCT signatures
GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates
GoDaddy: CA Certificates with HTTPS URL in AIA Field
GoDaddy: Partitioned CRL files missing Issuing Distribution Point
GoDaddy: CA Certificates Published in PEM format
GoDaddy: Delayed CRL File Updates
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB