← GoDaddy cases
Bugzilla #1567061 Policy Compliance

GoDaddy: inconsistent disclosure of externally-operated intermediate

RESOLVED FIXED GoDaddy
AI Summary

The case involves GoDaddy's inconsistent disclosure regarding cross-certificates that were issued under different Certificate Policies/Certificate Practice Statements (CP/CPS). Initially, GoDaddy disclosed these certificates as being under their CP/CPS, despite the fact that the root certificate controlling them had been transferred to Amazon Trust Services. This led to confusion and concerns about compliance with Mozilla's incident reporting guidelines. GoDaddy has since acknowledged the issue and is working on updating their audit reports to reflect the correct disclosures.

Model: gpt-4o-mini Generated: 2026-06-13 18:18 UTC Confidence: 0.90
Chronology
  1. GoDaddy disclosed intermediates operated under the same CP/CPS as parent.
  2. GoDaddy acknowledged the inquiry and committed to a community response.
  3. GoDaddy clarified the misunderstanding regarding the cross-certificates.
  4. GoDaddy submitted updated audit reports for review.
  5. The issue was deemed resolved from an audit perspective.
Participants
Andrew Ayer Joanna Ryan Sleevi W. Thayer
Similar Local Cases
#1713976 RESOLVED Policy Compliance Opened 2021-06-02 · Closed 2023-02-22 · 58% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods
#1713978 RESOLVED Policy Compliance Opened 2021-06-02 · Closed 2023-02-22 · 58% similar
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 57% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1549861 RESOLVED Policy Compliance Opened 2019-05-07 · Closed 2023-02-22 · 57% similar
Camerfirma: Outdated audit statements for intermediate certs
#1596949 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2023-02-22 · 56% similar
FNMT: CP/CPS lack CAA processing details
#1596923 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2024-06-30 · 54% similar
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
#1397830 RESOLVED Policy Compliance Opened 2017-09-07 · Closed 2023-02-22 · 54% similar
EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
#1037907 RESOLVED Policy Compliance Opened 2014-07-12 · Closed 2022-11-14 · 51% similar
GoDaddy: Valid 1024 certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action