← GlobalSign nv-sa cases
Bugzilla #1315018 Certificate Misissuance

SHA-1 issuance by GlobalSign root

RESOLVED WONTFIX GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Gervase Markham reported that crt.sh/cablint lists three intermediate certificates issued in 2016 that use SHA-1 and were issued directly by the “GlobalSign Root CA,” which is trusted by Mozilla to issue server certificates. He stated this issuance violates the Baseline Requirements and asked GlobalSign to explain why SHA-1 was used, the audit status of the relevant issuing CA(s), how the SHA-1 intermediates were issued, and what technical controls were in place to prevent SHA-1 issuance. GlobalSign responded that it generated some SHA-1 CAs earlier in 2016 as part of normal CA lifecycle management to support S/MIME and client authentication products, and that they were not intended for SSL certificate issuance. GlobalSign also said these CAs were disclosed to Mozilla in March 2016 shortly after creation, and it argued that Mozilla policy language about server authentication created ambiguity about whether the SHA-1 prohibition applied. Gerv replied that the Baseline Requirements and Mozilla policy both use intent-based language and that it was unclear whether the SHA-1 ban applied to certificates not intended for server use, noting a discussion in m.d.s.policy to address the loophole. The bug is marked RESOLVED with resolution WONTFIX.

Model: gpt-5.4-nano Generated: 2026-06-13 14:08 UTC Revised: 2026-06-16 18:37 UTC Confidence: 0.86 4 comments
Chronology
  1. A Mozilla CA Program bug was opened regarding SHA-1 intermediate certificates issued by GlobalSign Root CA.
  2. GlobalSign provided an explanation that the SHA-1 intermediates were generated for S/MIME and client authentication and not for SSL issuance.
Thread Activity
  1. Mozilla representative — Reported that crt.sh/cablint shows three SHA-1 intermediate certificates issued in 2016 by GlobalSign Root CA and asked GlobalSign to explain the apparent Baseline Requirements violation and related controls/audit status.
  2. Mozilla representative — Asked Steve to look into the issue and update the bug with the requested information.
  3. Community commenter — Explained that GlobalSign generated SHA-1 CAs for S/MIME and client authentication lifecycle management, disclosed them to Mozilla in March 2016, and argued they were not intended for SSL certificate issuance; also discussed reasons for not applying technical constraints such as EKU.
  4. Mozilla representative — Responded that the Baseline Requirements and Mozilla policy use intent-based language, creating ambiguity about whether the SHA-1 ban applies to certificates not intended for server use, and noted a policy discussion to remedy the loophole.
Participants
Mozilla representative Community commenter
Similar Local Cases
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 83% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1420766 RESOLVED Certificate Misissuance Opened 2017-11-26 · Closed 2024-05-09 · 82% similar
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1353833 RESOLVED Certificate Misissuance Validation Issue Opened 2017-04-05 · Closed 2023-02-22 · 80% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 78% similar
GlobalSign: CRL contains invalid signature algorithm
#1425478 RESOLVED Certificate Misissuance Opened 2017-12-15 · Closed 2024-05-09 · 78% similar
GlobalSign: Invalid Common Names in Globalsign Certificates
#682956 RESOLVED Certificate Misissuance Opened 2011-08-29 · Closed 2022-11-14 · 75% similar
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
#1398428 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 75% similar
Amazon Trust Services: CAA Misissuances
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 74% similar
DigiCert: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action