← GlobalSign nv-sa cases
Bugzilla #1393555 Self Reported Incident Incident

GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns GlobalSign's issuance of certificates containing non-compliant DNS names with double dots. The issue was identified through a problem report, prompting GlobalSign to investigate and disclose the findings. GlobalSign confirmed that they had ceased issuing such certificates after implementing a patch in February 2016. They provided a detailed report of the affected certificates, including a CSV file of fingerprints. The CA has committed to enhanced auditing practices to prevent future occurrences and has resolved the immediate issues by revoking the problematic certificates.

Model: gpt-4o-mini Generated: 2026-06-13 17:07 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.85 17 comments
Chronology
  1. GlobalSign implemented a patch addressing CN and SAN validation deficiencies.
  2. GlobalSign disclosed the issue of non-compliant certificate issuance.
  3. GlobalSign revoked the certificate with an invalid SAN.
Thread Activity
  1. Mozilla representative — This bug is in regards to the problem: invalid dnsNames containing 'double dots'.
  2. Community commenter — Problem report received and we're working on answers to the 7 questions above.
  3. Community commenter — We found 5 certificates issued under GlobalSign roots with the double-dot issue.
  4. Community commenter — We completed the review process and found 2 certificates with '..' in the SAN.
  5. Community commenter — GlobalSign is doing 100% audits starting for the month of September.
Participants
Mozilla representative Community commenter
External References
Similar Local Cases
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 99% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 98% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 97% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1554259 RESOLVED Self Reported Incident Security Incident Opened 2019-05-24 · Closed 2023-02-22 · 95% similar
GlobalSign: SPKI lacks explicit NULL parameter,
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 94% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 93% similar
GlobalSign: Invalid stateOrProvinceName and locality pair

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action