← GlobalSign nv-sa cases
Bugzilla #1301545 Certificate Misissuance

GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that the GlobalSign CloudSSL CA - SHA256 - G3 issued a certificate missing required extensions. Mozilla’s Dana Keeler noted the certificate had no subject alternative name (SAN) extension, no authority information access extension, and no certificate policies extension, and linked to a crt.sh entry for the certificate. GlobalSign stated that an engineer performed issuance based on a test CSR for a domain owned by GMO GlobalSign KK to check issuance speed, and that direct issuance was incorrectly used in a way that bypassed policy controls, resulting in the missing extensions. GlobalSign said the mistake was realized within 71 minutes and the certificate was revoked. GlobalSign also indicated it would amend its system to enforce policy from direct manual issuance as well as from system issuance. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:05 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.86 6 comments
Chronology
  1. GlobalSign CloudSSL CA - SHA256 - G3 issued a test certificate that lacked required extensions.
  2. GlobalSign revoked the misissued certificate after identifying the error.
Thread Activity
  1. Mozilla representative — Reported that GlobalSign CloudSSL CA - SHA256 - G3 issued a certificate without SAN, authority information access, and certificate policies extensions and provided a crt.sh link.
  2. Community commenter — Asked Steve and Richard to resolve the bug.
  3. GlobalSign nv-sa — Explained the certificate was issued from a test CSR using direct issuance that bypassed policy controls; said the mistake was realized within 71 minutes, the certificate was revoked, and described system changes to enforce policy for direct manual issuance; provided revocation evidence.
Participants
Mozilla representative Community commenter GlobalSign nv-sa
External References
Similar Local Cases
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 88% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 87% similar
GlobalSign Partner: No SAN
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 80% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1870276 RESOLVED Certificate Misissuance Opened 2023-12-15 · Closed 2024-01-24 · 80% similar
GlobalSign: TLS OV Certificate containing unverified information
#1650018 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 80% similar
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 79% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 79% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 79% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action