← GoDaddy cases
Bugzilla #2028195 Ca Documents

GoDaddy: inconsistent CP/CPS disclosure metadata in CCADB

RESOLVED INVALID GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports an inconsistency in GoDaddy’s CCADB metadata for an intermediate certificate. Andrew Ayer noted that for the intermediate with fingerprint 7a43bc7747d0633fbd90ff900c9242417c027dbdca05af72da9a70e3518dbe2e, GoDaddy disclosed CP/CPS as the same as the parent in CCADB record 001TO00000WaSbGYAV, but the parent record 001TO00000WaH9aYAF did not have a CP/CPS value and instead used an MD/AsciiDoc CP/CPS field. Andrew stated this inconsistency prevents programmatic determination of the intermediate’s CP/CPS. GoDaddy investigated and updated the applicable intermediate records in CCADB by unchecking “CP/CPS Same as Parent” and checking “MD/AsciiDoc CP/CPS Same as Parent.” GoDaddy also stated that the CP/CPS itself was already correctly disclosed and publicly available via the parent record, and that the issue was limited to metadata consistency and did not affect policy disclosure or compliance requirements. GoDaddy requested the bug be marked invalid and resolved, and the bug status is RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.86 4 comments
Chronology
  1. Andrew Ayer reported a CCADB metadata inconsistency for a GoDaddy intermediate’s CP/CPS disclosure relative to its parent record.
  2. GoDaddy updated CCADB metadata for applicable intermediate records to correct the CP/CPS/MD-AsciiDoc CP/CPS “same as parent” settings.
  3. GoDaddy asked that the bug be marked invalid and resolved after remediation and monitoring.
Thread Activity
  1. Mm representative — Reported that an intermediate record indicated CP/CPS was the same as parent, but the parent record lacked CP/CPS and used MD/AsciiDoc CP/CPS instead, making CP/CPS determination programmatically impossible.
  2. GoDaddy — Acknowledged the inconsistency and said GoDaddy CA was investigating and would take appropriate action shortly.
  3. GoDaddy — Confirmed GoDaddy fixed the CCADB metadata inconsistency by updating intermediate records’ “CP/CPS Same as Parent” and “MD/AsciiDoc CP/CPS Same as Parent” flags, and stated the CP/CPS was already correctly disclosed via the parent record.
  4. GoDaddy — Stated GoDaddy would continue monitoring and suggested marking the bug invalid and resolved if no further questions/comments.
Participants
Mm representative GoDaddy
External References
Similar Local Cases
#1706976 RESOLVED Ca Documents Opened 2021-04-22 · Closed 2022-11-14 · 67% similar
Google Trust Services: Out-of-date CPS disclosure
#1941675 RESOLVED Ca Documents Incident Opened 2025-01-14 · 66% similar
Certum root lists a Microsec CPS in AllCertificateRecordsCSVFormatv2
#1967951 RESOLVED Ca Documents Opened 2025-05-22 · Closed 2025-07-01 · 60% similar
FNMT: Delayed Disclosure of Updated Policy Documents in the CCADB
#1812336 RESOLVED Ca Documents Opened 2023-01-25 · Closed 2023-02-10 · 59% similar
Sectigo: Late CCADB update after CPS update
#1814197 RESOLVED Ca Documents Opened 2023-01-31 · Closed 2023-02-14 · 59% similar
DigiCert: Late CP/CPS CCADB uploads
#1716670 RESOLVED Ca Documents Audit Finding Opened 2021-06-15 · Closed 2024-06-30 · 59% similar
TWCA: Intermediate CA Certificate Missing from Audit Reports
#1374381 RESOLVED Ca Documents Opened 2017-06-19 · Closed 2023-02-22 · 59% similar
SwissSign: BRs require full annual audits
#1896959 RESOLVED Ca Documents Opened 2024-05-15 · Closed 2025-06-13 · 59% similar
KIR S.A. CCADB Test Documents

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action