GoDaddy: CCADB CRL disclosure mismatch for G2 intermediates, with R1 migration nearly complete
GoDaddy reported a CCADB compliance issue involving a mismatch between the CRL disclosures in CCADB and the CRL URLs listed in issued certificates for its G2 signing intermediates. The report says the non-compliance began on 2025-07-15 and was identified on 2025-12-19 after a Certificate Problem Report alerted GoDaddy to the mismatch. GoDaddy updated some CCADB entries, published a JSON file with the full CRL array in its GitHub repository, and said one G2 intermediate was brought into compliance while another remained blocked by CCADB field character limits. GoDaddy also said it is transitioning issuance to its R1 root hierarchy, has migrated 99% of issuance there, and is limiting remaining G2-issued certificates to 90-day validity. The thread states that GoDaddy plans to revoke the GoDaddy G2 Intermediate in January 2027 after all certificates issued from it have expired. The bug remains open and GoDaddy asked for a next update date of 2026-09-15.
- CCADB Policy 2.0 takes effect, and the CRL disclosure mismatch period begins.
- A Certificate Problem Report alerts GoDaddy to the CRL disclosure mismatch.
- GoDaddy updates R1 signing intermediate CCADB entries with partitioned CRL JSON arrays.
- GoDaddy says one G2 intermediate is compliant and another remains blocked by CCADB field limits.
- GoDaddy reports 99% of issuance has migrated to the R1 root hierarchies.
- GoDaddy — GoDaddy opens a preliminary incident report describing a CRL disclosure mismatch in CCADB and says a full investigation is underway.
- GoDaddy — GoDaddy files the full incident report, identifies the non-compliance as a CCADB Policy 6.2 exact-match issue, and says issuance was not stopped because there was no certificate misissuance.
- CCADB representative — CCADB says the report has gone stale and reminds GoDaddy about the Next update field.
- GoDaddy — GoDaddy says its CCADB policy review is complete, disclosures are up to date, and it is working with two root store programs to remove code signing and S/MIME trust bits from its roots.
- GoDaddy — GoDaddy says it has completed monitoring of CCADB disclosures and now monitors active CA certificates for valid audits, CRL, and CP/CPS disclosures.
- GoDaddy — GoDaddy says one G2 intermediate is now in compliance, another remains blocked by CCADB character limits, and it intends to revoke the G2 intermediate after unexpired subscriber certificates expire.
- GoDaddy — GoDaddy corrects a typo and states it plans to revoke the G2 intermediate in January 2027.
- GoDaddy — GoDaddy says it has migrated 99% of issuance to R1, is limiting remaining G2 certificates to 90-day validity, and asks for the next update date to be set to 2026-09-15.