GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
This case involves GlobalSign's issuance of certificates with RSA keys smaller than the required 2048 bits, which is a violation of the CA/Browser Forum's Baseline Requirements. The issue was identified by Mozilla, prompting a request for GlobalSign to disclose how they became aware of the problem and to provide a remediation plan. GlobalSign confirmed they have ceased issuing non-compliant certificates and provided a list of affected certificates. The CA has committed to monthly audits of all certificates issued by AT&T, their customer, and is transitioning AT&T to a hosted CA solution to prevent future occurrences. The case has been resolved with the implementation of these measures.
- GlobalSign acknowledged the issuance of non-compliant certificates and began remediation efforts.
- The case was closed following confirmation of the transition of AT&T to a hosted model.
- Mozilla representative — This bug is in regards to the problem: SA key smaller than 2048 bits.
- Community commenter — We've had several exchanges with AT&T and here is the latest status on the certificates.
- Community commenter — We have reinforced several times the importance of compliance to AT&T.
- Mozilla representative — Given that AT&T is being transitioned to a hosted model, we can call this closed.