← GoDaddy cases
Bugzilla #2004845 Self Reported Incident

GoDaddy: CA Certificates Published in PEM format

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosed incident by GoDaddy regarding the format of CA certificate files hosted behind the CA Issuers URI (AIA) on issued certificates. GoDaddy reported that two GoDaddy CA certificate files referenced in the AIA CA Issuers URI were being served in PEM format instead of the required DER-encoded format. GoDaddy stated that the non-compliance began on 2025-09-24 and was identified on 2025-12-06, and that it ended on 2025-12-08 after remediation. GoDaddy updated the hosted CA certificate files to the DER format and deployed monitoring to ensure hosted files are DER format for CA Issuer URIs. In the thread, GoDaddy also provided root cause analysis and action items, including updating CA certificate generation procedures to explicitly validate that AIA issuer URLs resolve to the correct DER-encoded CA certificate files and enhancing monitoring using SHA-256 thumbprint validation. GoDaddy requested closure of the incident report, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.90 10 comments
Chronology
  1. GoDaddy created cross-signed CA certificates with AIA CA Issuers values that later proved to reference CA certificate files hosted in the wrong (PEM) format.
  2. GoDaddy identified the non-compliance after certificate problem reporting indicated the hosted CA certificate file format issue.
  3. GoDaddy deployed updated DER-encoded CA files for the affected G2 root certificates behind the CA Issuers URI.
  4. GoDaddy deployed monitoring for CA Issuer URIs to verify hosted files are DER format.
  5. GoDaddy reported completion of action items and requested closure of the incident report.
Thread Activity
  1. GoDaddy — GoDaddy opened a preliminary incident report stating that two CA certificate files referenced in issued certificates’ AIA CA Issuers URI were served in PEM format and that the hosted files were updated to DER while investigation continued.
  2. GoDaddy — GoDaddy posted a full incident report with timeline, impact (2 certificates, 0 remaining valid), root cause analysis, and remediation details, and referenced related bugs including 2004492, 2004492, and others.
  3. GoDaddy — GoDaddy created an attachment (appendix CSV) for the bug.
  4. GoDaddy — GoDaddy stated it was continuing to monitor the incident and that remaining action items were still in progress.
  5. GoDaddy — GoDaddy reported continued monitoring, progress on open action items, and no further update.
  6. GoDaddy — GoDaddy stated it continued to monitor and was making progress on open action items.
  7. GoDaddy — GoDaddy said it expected remaining action items to be completed that week.
  8. GoDaddy — GoDaddy provided an action items update describing procedure and monitoring changes, including DER validation and SHA-256 thumbprint-based monitoring.
  9. GoDaddy — GoDaddy posted a report closure summary stating remediation was completed, action items were completed, and requested closure.
  10. CCADB representative — CCADB incident reporting issued a final call for comments and noted the bug would be closed approximately 2026-02-11.
Participants
GoDaddy CCADB representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2007217 RESOLVED Self Reported Incident Opened 2025-12-20 · Closed 2026-04-17 · 96% similar
GoDaddy: Partitioned CRL files missing Issuing Distribution Point
#2007216 ASSIGNED Ca Certificate Compliance Incident Ccadb Disclosure Issue Problem Reporting Failure Opened 2025-12-20 Still Open · 95% similar
GoDaddy: CRL Disclosure in CCADB Mismatch with Issued Certificates
#2002402 RESOLVED Self Reported Incident Opened 2025-11-25 · Closed 2026-01-13 · 92% similar
GoDaddy: Missing R1 Intermediate Full CRL URLs in CCADB
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 82% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#1577913 RESOLVED Self Reported Incident Opened 2019-08-30 · Closed 2023-02-22 · 82% similar
GoDaddy: Issues with State and Country fields
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 81% similar
GoDaddy: cross certificate disclosure to CCADB
#1605804 RESOLVED Self Reported Incident Opened 2019-12-24 · Closed 2023-02-22 · 81% similar
GoDaddy: Domain Validation Reuse Issue
#1341014 RESOLVED Self Reported Incident Opened 2017-02-20 · Closed 2023-02-22 · 80% similar
GoDaddy: Action Items

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action