← GlobalSign nv-sa cases
Bugzilla #1304089
Certificate Problem Report
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
RESOLVED
GlobalSign nv-sa
AI Summary
A bug in GlobalSign's Certificate Centre led to 68 SSL certificates being issued without the required Extended Key Usage (EKU) extension. This issue arose after a code update and affected both Extended Validation (EV) and Organizationally Validated (OV) certificates. GlobalSign has since identified and revoked all impacted certificates, and an emergency fix has been implemented to prevent future occurrences.
Chronology
- Bug reported by GlobalSign
- All affected certificates were revoked
- GlobalSign confirmed all impacted certs have been identified and revoked
- Bug closed as fixed
Participants
Steve Roylance
Kathleen Wilson
Gervase Markham
Douglas Beattie
External References
Similar Local Cases
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report
GlobalSign: IP in dnsName
GlobalSign: Invalid Common Names in Globalsign Certificates