GlobalSign Partner: No SAN
The bug was created after a certificate provided under GlobalSign’s “Virginia Tech Global Server CA” Partner Program was checked and found to be missing the Subject Alternative Name (SAN) extension. The reporter noted that, per CA/B Baseline Requirements section 9.2.1, end-entity certificates must include the SAN extension, but the attached certificate did not contain it. GlobalSign explained that the Partner Program had evolved over time and that the “Virginia Tech Global Server CA” entered revocation mode only, issuing CRLs only, and was replaced by a new Name Constrained CA (“Virginia Tech Global Qualified Server CA”) with SANs and name constraints. GlobalSign stated that the crossover to the new CA occurred in 2013 (March through September) and that corrective actions were made so that certificates issued from March 2013 onward include SANs. GlobalSign also reported that, at the time of the response, 428 certificates were still alive and 115 of them had SANs, while the new CA was issuing with SANs going forward. The bug was marked RESOLVED with resolution “WORKSFORME.”
- A certificate was reviewed and found to lack the SAN extension, prompting a Mozilla CA Program bug report.
- GlobalSign described the Partner Program transition to a replacement CA that issues certificates with SANs and name constraints.
- Ian representative — Created the bug with an attached certificate and reported that the certificate does not contain a SAN extension, contrary to CA/B Baseline Requirements 9.2.1.
- GlobalSign nv-sa — Explained that the old “Virginia Tech Global Server CA” moved to CRL-only revocation mode and was replaced in 2013 by a new Name Constrained CA that issues certificates with SANs and name constraints, and stated counts of still-alive certificates with SANs.
- GlobalSign nv-sa — Corrected the validity/expiry timing for the last certificate issued from the older system.