← GoDaddy cases
Bugzilla #708229 Common Ca Database Repository Issue

GoDaddy intermediate CA not included in Mozilla CA bundle

RESOLVED INVALID GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug report describes an SSL handshake failure when using cURL against a webserver configured with a valid GoDaddy class 2 certificate. The reporter attributes the failure to a missing GoDaddy intermediate CA certificate in the Mozilla CA bundle (as used by Linux ca-certificates), which they say causes the certificate chain to be reported as untrusted. The reporter asks Mozilla to add the GoDaddy intermediate certificate to the bundle and provides links to GoDaddy’s CA repository and the direct intermediate certificate URL. Mozilla staff responded that intermediate certificates are not included in the Mozilla root store/bundle and that servers should provide the full certificate chain. The bug was resolved as INVALID, with the rationale that the issue is due to server configuration rather than a Mozilla trust-store problem.

Model: gpt-5.4-nano Generated: 2026-06-13 12:18 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.86 4 comments
Chronology
  1. A third party reported that GoDaddy class 2 certificates fail SSL handshakes because the GoDaddy intermediate certificate is missing from the Mozilla CA bundle.
Thread Activity
  1. Community commenter — Reported that cURL SSL handshakes fail because the GoDaddy intermediate CA certificate is missing from the Mozilla CA bundle and requested it be added, including repository and direct certificate links.
  2. Mit representative — Asked who owns the CA bundle and what the Mozilla CA bundle is.
  3. Mversen representative — Explained that intermediate certificates are not included in the Mozilla CA bundle/root store and that servers must send the full chain.
  4. Mozilla representative — Confirmed Mozilla does not include intermediate certificates, and stated CAs should advise customers to configure servers with the full certificate chain.
Participants
Community commenter Mit representative Mversen representative Mozilla representative
Similar Local Cases
#1579299 RESOLVED Repository Issue Certificate Misissuance Opened 2019-09-06 · Closed 2023-02-22 · 68% similar
Asseco DS / Certum: non-audited intermediate certificate
#1320943 RESOLVED Revocation Issue Repository Issue Opened 2016-11-29 · Closed 2022-11-14 · 67% similar
Add revoked certificate Certification Authority of WoSign G2 issued by Certum CA root to OneCRL
#1391095 RESOLVED Common Ca Database Opened 2017-08-16 · Closed 2022-11-14 · 66% similar
Add AC FNMT Usuarios certificate to OneCRL
#1567061 RESOLVED Self Reported Incident Repository Issue Opened 2019-07-18 · Closed 2023-02-22 · 60% similar
GoDaddy: inconsistent disclosure of externally-operated intermediate
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 59% similar
Certigna: Pre-certificates not recognised by the OCSP responder
#2013375 RESOLVED Ca Documents Common Ca Database Opened 2026-01-29 · Closed 2026-02-18 · 59% similar
DigiCert: Issues with CCADB entries
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 59% similar
D-Trust: CRL URL Disclosure
#2049179 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-21 Still Open · 58% similar
CFCA: OCSP Service return unauthorized responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action