← GlobalSign nv-sa cases
Bugzilla #1393555
Self Reported Incident
Incident
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case concerns GlobalSign's issuance of certificates containing non-compliant DNS names with double dots. The issue was identified through a problem report, prompting GlobalSign to investigate and disclose the findings. GlobalSign confirmed that they had ceased issuing such certificates after implementing a patch in February 2016. They provided a detailed report of the affected certificates, including a CSV file of fingerprints. The CA has committed to enhanced auditing practices to prevent future occurrences and has resolved the immediate issues by revoking the problematic certificates.
Chronology
- GlobalSign implemented a patch addressing CN and SAN validation deficiencies.
- GlobalSign disclosed the issue of non-compliant certificate issuance.
- GlobalSign revoked the certificate with an invalid SAN.
Thread Activity
- Mozilla representative — This bug is in regards to the problem: invalid dnsNames containing 'double dots'.
- Community commenter — Problem report received and we're working on answers to the 7 questions above.
- Community commenter — We found 5 certificates issued under GlobalSign roots with the double-dot issue.
- Community commenter — We completed the review process and found 2 certificates with '..' in the SAN.
- Community commenter — GlobalSign is doing 100% audits starting for the month of September.
Participants
Mozilla representative
Community commenter
External References
Similar Local Cases
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
GlobalSign: 4 Misissued certificates with invalid CN
GlobalSign: SPKI lacks explicit NULL parameter,
GlobalSign: SSL Certificates with US country code and invalid State/Prov
GlobalSign: Invalid stateOrProvinceName and locality pair