Public disclosure of GlobalSign Subordinate CAs
This case is a public disclosure by GlobalSign of its subordinate CAs that are not technically constrained, following Mozilla’s CA Inclusion Policy instructions. The bug was created to provide the full DER-encoded X.509 certificates for each issuing CA’s non-technically-constrained intermediate certificates, packaged in a zip attachment. The thread also includes links to GlobalSign’s certificate policy and certification practice statements (CP/CPS) and references to GlobalSign’s WebTrust audit materials. GlobalSign stated that the WebTrust audit was ongoing (April through May) and provided links to WebTrust seal files for CA, Baseline Requirements, and EV. The bug was closed as resolved, with the note that it would continue to be used to provide information about GlobalSign’s publicly disclosed and audited subordinate CAs per the referenced Mozilla inclusion policy. Later comments indicate GlobalSign continued updating the disclosed CA lists, including an updated March 2015 list and additional zip attachments, with most newer CAs being name constrained and therefore not disclosed in this process.
- GlobalSign opened a Mozilla CA Program bug to disclose non-technically-constrained subordinate CAs per the Inclusion Policy and attached the required certificate and policy/audit information.
- The bug was closed as resolved while continuing to be used as an information source for publicly disclosed and audited subordinate CAs.
- GlobalSign provided updated disclosed CA lists and additional disclosure zip attachments reflecting changes as of March 2015.
- GlobalSign nv-sa — Created the disclosure bug and attached a zip containing non-technically-constrained intermediate certificates, stating it was raised per the Inclusion Policy.
- GlobalSign nv-sa — Provided the Inclusion Policy-required items, including links to GlobalSign CP/CPS PDFs and WebTrust seal files for CA, Baseline Requirements, and EV.
- Mozilla representative — Closed the bug as resolved, stating it would continue to be used to provide information about GlobalSign’s publicly disclosed and audited subordinate CAs per the referenced Mozilla inclusion policy item.
- GlobalSign nv-sa — Attached an updated spreadsheet/list of issuing CAs and stated that most new CAs are name constrained and therefore not disclosed, with further updates planned via another zip attachment.
- GlobalSign nv-sa — Attached an updated March 2015 spreadsheet with unconstrained and constrained CAs.
- GlobalSign nv-sa — Attached an updated zip of GlobalSign subordinate CAs for disclosure.