GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB
GoDaddy reported a CCADB compliance incident involving missing full CRL URLs for its R1 intermediate certificates. The issue was disclosed via Certificate Problem Reporting and described as missing full CRL distribution point URLs on the GoDaddy and Starfield R1 intermediate certificate CCADB entries. GoDaddy stated that CCADB policy 6.2 requires the full CRL URL to be updated within 7 days of the first certificate issued by the CA certificate, and that the non-compliance window ran from 2025-10-09 20:37:27 to 2025-11-25 18:00. GoDaddy confirmed that all 6 impacted R1 intermediate certificates had their CCADB entries updated with the full CRL distribution URLs, and it also updated its internal root and intermediate generation playbook to include CCADB disclosures of full CRLs within 7 days of first issuance. In the closure request, GoDaddy reported that the action items in the incident report were completed and asked for the bug’s closure. The bug is marked RESOLVED with resolution FIXED.
- GoDaddy’s R1 root hierarchy began issuing leaf certificates.
- GoDaddy received a Certificate Problem Report indicating missing full CRL URLs in CCADB for impacted R1 intermediate certificates.
- GoDaddy updated CCADB entries for the impacted R1 intermediates with full CRL distribution URLs.
- GoDaddy updated its internal generation playbook to include CCADB full CRL URL disclosures within 7 days of first issuance.
- GoDaddy — Opened the incident report, stating that CRL Distribution Points were missing in CCADB for R1 intermediate certificates and that a full investigation was in progress.
- GoDaddy — Provided the full incident report, including the timeline, policy basis (CCADB policy 6.2), and that CCADB entries for 6 impacted R1 intermediates were updated with full CRL URLs.
- GoDaddy — Requested closure, stating the root causes were gaps in internal documentation and missed documentation updates, and that remediation was updating the R1 intermediate CCADB entries with full CRL distribution URLs.
- CCADB representative — Issued a final call for comments or questions and indicated the incident report would be closed around 2025-12-24.
- Google representative — Asked GoDaddy to investigate CCADB CSV report entries showing missing CRL disclosures for the GoDaddy TLS Root CA - R1 and Starfield TLS Root CA - R1.
- Community commenter — Asked whether GoDaddy responded to question five within seven days per the CCADB incident report guidance.
- GoDaddy — Responded that cross signed intermediates were updated in CCADB with accurate full CRL URLs, explained they were overlooked because they do not directly issue certificates, and referenced a related ongoing incident (bug 2007216) about a mismatch on issued certificates.
- CCADB representative — Issued another final call for comments or questions and indicated closure around 2026-01-13.