SHA-1 issuance by GlobalSign root
Gervase Markham reported that crt.sh/cablint lists three intermediate certificates issued in 2016 that use SHA-1 and were issued directly by the “GlobalSign Root CA,” which is trusted by Mozilla to issue server certificates. He stated this issuance violates the Baseline Requirements and asked GlobalSign to explain why SHA-1 was used, the audit status of the relevant issuing CA(s), how the SHA-1 intermediates were issued, and what technical controls were in place to prevent SHA-1 issuance. GlobalSign responded that it generated some SHA-1 CAs earlier in 2016 as part of normal CA lifecycle management to support S/MIME and client authentication products, and that they were not intended for SSL certificate issuance. GlobalSign also said these CAs were disclosed to Mozilla in March 2016 shortly after creation, and it argued that Mozilla policy language about server authentication created ambiguity about whether the SHA-1 prohibition applied. Gerv replied that the Baseline Requirements and Mozilla policy both use intent-based language and that it was unclear whether the SHA-1 ban applied to certificates not intended for server use, noting a discussion in m.d.s.policy to address the loophole. The bug is marked RESOLVED with resolution WONTFIX.
- A Mozilla CA Program bug was opened regarding SHA-1 intermediate certificates issued by GlobalSign Root CA.
- GlobalSign provided an explanation that the SHA-1 intermediates were generated for S/MIME and client authentication and not for SSL issuance.
- Mozilla representative — Reported that crt.sh/cablint shows three SHA-1 intermediate certificates issued in 2016 by GlobalSign Root CA and asked GlobalSign to explain the apparent Baseline Requirements violation and related controls/audit status.
- Mozilla representative — Asked Steve to look into the issue and update the bug with the requested information.
- Community commenter — Explained that GlobalSign generated SHA-1 CAs for S/MIME and client authentication lifecycle management, disclosed them to Mozilla in March 2016, and argued they were not intended for SSL certificate issuance; also discussed reasons for not applying technical constraints such as EKU.
- Mozilla representative — Responded that the Baseline Requirements and Mozilla policy use intent-based language, creating ambiguity about whether the SHA-1 ban applies to certificates not intended for server use, and noted a policy discussion to remedy the loophole.