← GlobalSign nv-sa cases
Bugzilla #1304089 Certificate Misissuance

GlobalSign Certificate Centre bug issued 68 (later 11 more) SSL certificates with missing EKU/KU; revoked and fixed

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that after a recent code update to its GlobalSign Certificate Centre (GCC) platform, re-issued SSL certificates with modified Subject Alternative Name domains could fail to populate Extended Key Usage (EKU), resulting in certificates with no EKU at all. GlobalSign stated that it identified 68 affected certificates (4 EV and 64 OV) and that EV certificates were already revoked and present on the EV CRL, while OV certificates were revoked via CRL/OCSP with remaining OV certificates appearing in the next CRL publication. GlobalSign said it installed an emergency fix and that support teams contacted impacted customers to perform revocations. In a later update, GlobalSign reported an additional investigation found 11 more OV certificates without KU and EKU caused by the same code bug, and stated these 11 certificates were revoked via CRL and OCSP by 11 October. Mozilla participants discussed whether the certificates needed to be added to OneCRL, and GlobalSign’s assigned reviewer agreed there were no further action items. The bug was resolved as FIXED, with agreement that the impacted certificates had been identified and revoked.

Model: gpt-5.4-nano Generated: 2026-06-13 14:05 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.86 10 comments
Chronology
  1. GlobalSign identified a GCC code bug that could issue SSL certificates without EKU/KU and began revoking affected certificates via CRL/OCSP after an emergency fix.
  2. GlobalSign reported that an additional set of 11 affected OV certificates were revoked via CRL and OCSP.
  3. Mozilla agreed the bug could be closed as fixed with no need to add the certificates to OneCRL.
Thread Activity
  1. GlobalSign nv-sa — Reported that a GCC code update caused 68 re-issued SSL certificates to be issued without EKU (empty EKU), and stated GlobalSign was revoking the affected certificates after installing an emergency fix.
  2. GlobalSign nv-sa — Confirmed remaining certificates were recorded in the CRL issued at 12:00 GMT, noted an earlier serial-listing mistake, and stated the last listed certificate was also revoked.
  3. Mozilla representative — Asked whether the issue was an EKU extension with no EKUs versus a missing EKU, and requested clarification on reported client experience.
  4. GlobalSign nv-sa — Clarified that the EKU was missing (no EKU at all) and offered to have support comment if specific client failures were identified.
  5. Mozilla representative — Suggested checking with other subscribers and resending if the failure seemed global.
  6. Community commenter — Provided a CAB Forum public mailing list URL for the disclosure email.
  7. Community commenter — Commented that the email may have been flagged as spam due to DMARC configuration and suggested checking mailman/domain settings.
  8. GlobalSign nv-sa — Updated that 11 additional OV certificates without KU and EKU were found due to the same code bug, and stated they were revoked via CRL and OCSP by 11 October.
  9. Mozilla representative — Agreed the issue was fixed and all impacted certs were identified and revoked, and asked whether there was any disagreement about not adding them to OneCRL.
  10. Mozilla representative — Agreed the bug could be closed and stated there was no need to add the certificates to OneCRL.
Participants
GlobalSign nv-sa Mozilla representative Community commenter
Similar Local Cases
#1420766 RESOLVED Certificate Misissuance Opened 2017-11-26 · Closed 2024-05-09 · 100% similar
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1536760 RESOLVED Certificate Misissuance Opened 2019-03-20 · Closed 2023-02-22 · 96% similar
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 88% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 88% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 88% similar
GlobalSign Partner: No SAN
#1301545 RESOLVED Certificate Misissuance Opened 2016-09-08 · Closed 2022-11-14 · 88% similar
GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 88% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 84% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action