← GlobalSign nv-sa cases
Bugzilla #1390997 Ca Certificate Compliance Incident Revocation Issue

GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves GlobalSign's disclosure of non-compliant certificate issuance related to metadata-only subject fields. The CA became aware of the issue through internal audits and discussions in the mozilla.dev.security.policy forum. GlobalSign confirmed that it had stopped issuing certificates with problematic metadata and provided a detailed report of the affected certificates. The CA implemented additional checks to prevent future occurrences and initiated revocation of the non-compliant certificates. The issue was resolved after the necessary fixes were deployed and all identified certificates were revoked.

Model: gpt-4o-mini Generated: 2026-06-13 17:04 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.85 15 comments
Chronology
  1. GlobalSign disclosed non-compliance issues with issued certificates.
  2. GlobalSign implemented fixes and revoked the identified non-compliant certificates.
Thread Activity
  1. Mozilla representative — GlobalSign was informed of compliance issues and required to provide a remediation plan.
  2. GlobalSign nv-sa — GlobalSign confirmed the issuance of certificates with metadata-only fields and outlined steps taken to address the issue.
  3. Community commenter — GlobalSign reported that the fix was implemented and all identified certificates were revoked.
Participants
Mozilla representative GlobalSign nv-sa Community commenter Titanous representative
External References
Similar Local Cases
#1393555 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1623356 RESOLVED Ca Certificate Compliance Opened 2020-03-18 · Closed 2023-02-22 · 97% similar
GlobalSign: Misissuance of QWAC Certificates
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 95% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 93% similar
Disig: Non-BR-Compliant Certificate Issuance
#1391066 RESOLVED Ca Certificate Compliance Opened 2017-08-16 · Closed 2023-02-22 · 92% similar
SwissSign: Non-BR-Compliant Certificate Issuance
#1391055 RESOLVED Ca Certificate Compliance Incident Opened 2017-08-16 · Closed 2023-02-22 · 91% similar
Microsec: Non-BR-Compliant Certificate Issuance
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 90% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action