GlobalSign Certificate Centre bug issued 68 (later 11 more) SSL certificates with missing EKU/KU; revoked and fixed
GlobalSign reported that after a recent code update to its GlobalSign Certificate Centre (GCC) platform, re-issued SSL certificates with modified Subject Alternative Name domains could fail to populate Extended Key Usage (EKU), resulting in certificates with no EKU at all. GlobalSign stated that it identified 68 affected certificates (4 EV and 64 OV) and that EV certificates were already revoked and present on the EV CRL, while OV certificates were revoked via CRL/OCSP with remaining OV certificates appearing in the next CRL publication. GlobalSign said it installed an emergency fix and that support teams contacted impacted customers to perform revocations. In a later update, GlobalSign reported an additional investigation found 11 more OV certificates without KU and EKU caused by the same code bug, and stated these 11 certificates were revoked via CRL and OCSP by 11 October. Mozilla participants discussed whether the certificates needed to be added to OneCRL, and GlobalSign’s assigned reviewer agreed there were no further action items. The bug was resolved as FIXED, with agreement that the impacted certificates had been identified and revoked.
- GlobalSign identified a GCC code bug that could issue SSL certificates without EKU/KU and began revoking affected certificates via CRL/OCSP after an emergency fix.
- GlobalSign reported that an additional set of 11 affected OV certificates were revoked via CRL and OCSP.
- Mozilla agreed the bug could be closed as fixed with no need to add the certificates to OneCRL.
- GlobalSign nv-sa — Reported that a GCC code update caused 68 re-issued SSL certificates to be issued without EKU (empty EKU), and stated GlobalSign was revoking the affected certificates after installing an emergency fix.
- GlobalSign nv-sa — Confirmed remaining certificates were recorded in the CRL issued at 12:00 GMT, noted an earlier serial-listing mistake, and stated the last listed certificate was also revoked.
- Mozilla representative — Asked whether the issue was an EKU extension with no EKUs versus a missing EKU, and requested clarification on reported client experience.
- GlobalSign nv-sa — Clarified that the EKU was missing (no EKU at all) and offered to have support comment if specific client failures were identified.
- Mozilla representative — Suggested checking with other subscribers and resending if the failure seemed global.
- Community commenter — Provided a CAB Forum public mailing list URL for the disclosure email.
- Community commenter — Commented that the email may have been flagged as spam due to DMARC configuration and suggested checking mailman/domain settings.
- GlobalSign nv-sa — Updated that 11 additional OV certificates without KU and EKU were found due to the same code bug, and stated they were revoked via CRL and OCSP by 11 October.
- Mozilla representative — Agreed the issue was fixed and all impacted certs were identified and revoked, and asked whether there was any disagreement about not adding them to OneCRL.
- Mozilla representative — Agreed the bug could be closed and stated there was no need to add the certificates to OneCRL.