GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions
This case reports that the GlobalSign CloudSSL CA - SHA256 - G3 issued a certificate missing required extensions. Mozilla’s Dana Keeler noted the certificate had no subject alternative name (SAN) extension, no authority information access extension, and no certificate policies extension, and linked to a crt.sh entry for the certificate. GlobalSign stated that an engineer performed issuance based on a test CSR for a domain owned by GMO GlobalSign KK to check issuance speed, and that direct issuance was incorrectly used in a way that bypassed policy controls, resulting in the missing extensions. GlobalSign said the mistake was realized within 71 minutes and the certificate was revoked. GlobalSign also indicated it would amend its system to enforce policy from direct manual issuance as well as from system issuance. The bug was resolved as FIXED.
- GlobalSign CloudSSL CA - SHA256 - G3 issued a test certificate that lacked required extensions.
- GlobalSign revoked the misissued certificate after identifying the error.
- Mozilla representative — Reported that GlobalSign CloudSSL CA - SHA256 - G3 issued a certificate without SAN, authority information access, and certificate policies extensions and provided a crt.sh link.
- Community commenter — Asked Steve and Richard to resolve the bug.
- GlobalSign nv-sa — Explained the certificate was issued from a test CSR using direct issuance that bypassed policy controls; said the mistake was realized within 71 minutes, the certificate was revoked, and described system changes to enforce policy for direct manual issuance; provided revocation evidence.