← GoDaddy cases
Bugzilla #988633 Ca Certificate Compliance Certificate Misissuance

GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority

RESOLVED FIXED GoDaddy
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a certificate encoding problem in a certificate issued by Go Daddy Secure Certification Authority. Mozilla reported that the certificate’s basic constraints extension included the CA boolean value even when it was the default value false, and that this encoding caused mozilla::pkix to terminate the connection. A Go Daddy representative agreed the encoding was invalid and stated that Go Daddy would change its issuing profile to omit the CA basic constraint boolean when false on future certificates. Mozilla noted that this would be a considerable compatibility issue and referenced related mozilla::pkix work in other bugs. The bug was later marked Resolved/Fixed, with Mozilla stating that the underlying issue—GoDaddy’s encoding—had been reported as fixed, while any decision about deprecating the mozilla::pkix workaround might be tracked separately. The thread also discussed the relevant Baseline Requirements and RFC 5280 behavior for basicConstraints encoding.

Model: gpt-5.4-nano Generated: 2026-06-13 13:54 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.62 10 comments
Chronology
  1. Mozilla opened a CA Program compliance bug after identifying an invalid basicConstraints encoding in a Go Daddy Secure Certification Authority-issued certificate.
  2. Go Daddy agreed the certificate encoding was invalid and discussed the standards basis for the issue.
  3. Go Daddy committed to changing its issuing profile to omit the CA basic constraint boolean when false on future certificates.
  4. Mozilla discussed the compatibility impact and pointed to related mozilla::pkix work.
  5. Mozilla and participants discussed communications and transition time for CAs regarding mozilla::pkix-related findings.
  6. Mozilla marked the bug Resolved/Fixed after reporting that the underlying GoDaddy encoding issue was fixed.
Thread Activity
  1. Mozilla representative — Created the bug and attachment, stating the basicConstraints CA boolean was encoded as false even though it is the default, which caused mozilla::pkix to terminate the connection.
  2. Community commenter — Asked for clarification, citing Baseline Requirements and X.690 language about optional/default encodings and suggesting it sounded like a mozilla::pkix bug.
  3. Community commenter — Corrected the X.690 citation (SET vs SEQUENCE) and concluded the certificate was bad based on the default-value encoding rule.
  4. GoDaddy — Agreed the encoding was invalid and said Go Daddy would change its issuing profile to omit the CA basic constraint boolean when false on future certificates.
  5. Mozilla representative — Noted this would be a considerable compatibility issue and referenced prior workaround handling similar to other bugs.
  6. Mozilla representative — Pointed to separate mozilla::pkix work bugs and stated this bug would track communications and decisions with Go Daddy.
  7. Mozilla representative — Agreed with the approach and said she would add it to a list of things CAs should stop doing and communicate with CAs with transition time.
  8. Community commenter — Argued the Baseline Requirements already cover the issue and suggested it was not a new hole but a long-standing requirement.
  9. Briansmith representative — Agreed broadly and discussed minimizing workaround duration and the existence of stricter decoding in mozilla::pkix.
  10. Community commenter — Marked the bug Resolved/Fixed, stating the underlying GoDaddy encoding issue was reported fixed, while deprecating the mozilla::pkix workaround might be tracked separately.
Participants
Mozilla representative Community commenter GoDaddy Briansmith representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1391429 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-08-17 · Closed 2024-02-27 · 97% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 87% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1502957 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 87% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1330482 RESOLVED Certificate Misissuance Opened 2017-01-12 · Closed 2023-02-22 · 86% similar
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 80% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1639032 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-05-18 · Closed 2023-02-22 · 79% similar
DigiCert: "Internet Widgits Pty Ltd" in organizationalUnitName
#1777128 RESOLVED Certificate Misissuance Opened 2022-06-28 · Closed 2023-02-22 · 79% similar
GoDaddy: Misissuance of Cross Signed Certs
#1456655 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-04-24 · Closed 2023-02-22 · 78% similar
DigiCert / ABB: Issues with DN, country code and keyUsage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action