GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
This case was opened in response to a report posted in the mozilla.dev.security.policy forum about Incapsula “re-keying” certificates for domains that were no longer under subscriber control, including testslsslfeb20.me. GlobalSign stated that, for this specific domain, it had been verified within 39 months of issuance/reissuance, and described that domain vetting is normally performed just prior to issuance, allowing replacement up until expiration. Mozilla asked for details on how many of the 945 domains failed re-validation due to no longer being owned by the customer (or customer’s customer), noting that 39 months was too infrequent for rechecking ownership. GlobalSign later reported that 236 of the 945 SANs were deleted from certificates and not added back, and indicated this as an upper limit on domains that failed re-validation. Mozilla concluded that there was no further action at that time. The bug is marked RESOLVED with resolution FIXED.
- Bug opened regarding a reported Incapsula certificate re-keying issue involving testslsslfeb20.me.
- Mozilla requested clarification on the number of domains/SANs that failed re-validation and assessed the mitigation.
- GlobalSign provided the count of SANs deleted without being re-added as an upper limit for failed re-validation.
- Bug status updated to RESOLVED (resolution FIXED).
- Community commenter — Reported the forum thread and said GlobalSign was looking into the reported Incapsula/testslsslfeb20.me certificate and related questions, noting domain verification within 39 months for this specific case.
- Community commenter — Posted a response in the thread with a link to the forum message.
- Community commenter — Acknowledged the incident report, said lack of proper ownership validation is serious but mitigated here, and asked how many of 945 domains failed re-validation; also noted GlobalSign’s update to a new 825-day standard and planned voluntary 15-month standard.
- Community commenter — Provided that 236 of 945 SANs were deleted from certificates and not added back, as an upper limit on domains that failed re-validation.