← GlobalSign nv-sa cases
Bugzilla #1353833 Certificate Misissuance Validation Issue

GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was opened in response to a report posted in the mozilla.dev.security.policy forum about Incapsula “re-keying” certificates for domains that were no longer under subscriber control, including testslsslfeb20.me. GlobalSign stated that, for this specific domain, it had been verified within 39 months of issuance/reissuance, and described that domain vetting is normally performed just prior to issuance, allowing replacement up until expiration. Mozilla asked for details on how many of the 945 domains failed re-validation due to no longer being owned by the customer (or customer’s customer), noting that 39 months was too infrequent for rechecking ownership. GlobalSign later reported that 236 of the 945 SANs were deleted from certificates and not added back, and indicated this as an upper limit on domains that failed re-validation. Mozilla concluded that there was no further action at that time. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:13 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 4 comments
Chronology
  1. Bug opened regarding a reported Incapsula certificate re-keying issue involving testslsslfeb20.me.
  2. Mozilla requested clarification on the number of domains/SANs that failed re-validation and assessed the mitigation.
  3. GlobalSign provided the count of SANs deleted without being re-added as an upper limit for failed re-validation.
  4. Bug status updated to RESOLVED (resolution FIXED).
Thread Activity
  1. Community commenter — Reported the forum thread and said GlobalSign was looking into the reported Incapsula/testslsslfeb20.me certificate and related questions, noting domain verification within 39 months for this specific case.
  2. Community commenter — Posted a response in the thread with a link to the forum message.
  3. Community commenter — Acknowledged the incident report, said lack of proper ownership validation is serious but mitigated here, and asked how many of 945 domains failed re-validation; also noted GlobalSign’s update to a new 825-day standard and planned voluntary 15-month standard.
  4. Community commenter — Provided that 236 of 945 SANs were deleted from certificates and not added back, as an upper limit on domains that failed re-validation.
Participants
Community commenter
Similar Local Cases
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 80% similar
SHA-1 issuance by GlobalSign root
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 79% similar
GlobalSign: CRL contains invalid signature algorithm
#1425478 RESOLVED Certificate Misissuance Opened 2017-12-15 · Closed 2024-05-09 · 78% similar
GlobalSign: Invalid Common Names in Globalsign Certificates
#1347882 RESOLVED Trust Bit Disablement Certificate Misissuance Opened 2017-03-16 · Closed 2023-01-25 · 73% similar
GlobalSign: Remove EV bit from ex-GS roots now owned by GTS
#1301545 RESOLVED Certificate Misissuance Opened 2016-09-08 · Closed 2022-11-14 · 68% similar
GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 67% similar
DigiCert: TERENA: No localityName in EV precert
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 62% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 62% similar
Sectigo: potentially invalid organizational validation certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action