← GoDaddy cases
Bugzilla #1330482
Certificate Problem Report
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
RESOLVED
GoDaddy
AI Summary
This case addresses a regression in GoDaddy's certificate issuance process, which mirrors a previously reported issue from 2010. The user reported that GoDaddy's verification process allowed for incorrect certificate issuance under certain conditions, similar to past vulnerabilities. The case was resolved after discussions highlighted the need for GoDaddy to implement better preventative measures to avoid such regressions in the future.
Chronology
- Bug reported by user
- Bug closed and made public
Participants
Fred Emmott
Kathleen Wilson
Gervase Markham
Ryan Sleevi
External References
Similar Local Cases
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
GoDaddy's intermediate CA not in the Mozilla CA bundle
DigiCert / InfoCert: Insufficient Serial Number Entropy
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
DigiCert: no subject alternative name in Siemens certs
Camerfirma: Startcom are issuing by proxy using Camerfirma