← GlobalSign nv-sa cases
Bugzilla #1393555
Certificate Problem Report
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
This case concerns GlobalSign's issuance of certificates containing invalid DNS names with double dots. The issue was identified through a problem report, leading to an investigation into the certificates issued under GlobalSign roots. It was confirmed that three certificates were issued before a patch was implemented in February 2016 to address validation deficiencies. GlobalSign has since ceased issuing such certificates and has improved its auditing processes to prevent future occurrences.
Chronology
- Patch released to address CN and SAN validation deficiencies.
- Problem report received regarding double dots in dnsName.
- Certificate with invalid SAN was revoked.
Participants
Kathleen Wilson
Linus Hallberg
Douglas Beattie
Ryan Sleevi
External References
Similar Local Cases
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
GlobalSign: IP in dnsName
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report
Consorci AOC: Non-BR-Compliant Certificate Issuance
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs