GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
This case involves GlobalSign's disclosure of non-compliant certificate issuance related to metadata-only subject fields. The CA became aware of the issue through internal audits and discussions in the mozilla.dev.security.policy forum. GlobalSign confirmed that it had stopped issuing certificates with problematic metadata and provided a detailed report of the affected certificates. The CA implemented additional checks to prevent future occurrences and initiated revocation of the non-compliant certificates. The issue was resolved after the necessary fixes were deployed and all identified certificates were revoked.
- GlobalSign disclosed non-compliance issues with issued certificates.
- GlobalSign implemented fixes and revoked the identified non-compliant certificates.
- Mozilla representative — GlobalSign was informed of compliance issues and required to provide a remediation plan.
- GlobalSign nv-sa — GlobalSign confirmed the issuance of certificates with metadata-only fields and outlined steps taken to address the issue.
- Community commenter — GlobalSign reported that the fix was implemented and all identified certificates were revoked.