← GlobalSign nv-sa cases
Bugzilla #1393557 Self Reported Incident Incident

GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves GlobalSign's issuance of certificates with RSA keys smaller than the required 2048 bits, which is a violation of the CA/Browser Forum's Baseline Requirements. The issue was identified by Mozilla, prompting a request for GlobalSign to disclose how they became aware of the problem and to provide a remediation plan. GlobalSign confirmed they have ceased issuing non-compliant certificates and provided a list of affected certificates. The CA has committed to monthly audits of all certificates issued by AT&T, their customer, and is transitioning AT&T to a hosted CA solution to prevent future occurrences. The case has been resolved with the implementation of these measures.

Model: gpt-4o-mini Generated: 2026-06-13 17:07 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.85 21 comments
Chronology
  1. GlobalSign acknowledged the issuance of non-compliant certificates and began remediation efforts.
  2. The case was closed following confirmation of the transition of AT&T to a hosted model.
Thread Activity
  1. Mozilla representative — This bug is in regards to the problem: SA key smaller than 2048 bits.
  2. Community commenter — We've had several exchanges with AT&T and here is the latest status on the certificates.
  3. Community commenter — We have reinforced several times the importance of compliance to AT&T.
  4. Mozilla representative — Given that AT&T is being transitioned to a hosted model, we can call this closed.
Participants
Mozilla representative Community commenter
External References
Similar Local Cases
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 100% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1390997 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1393555 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 100% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 97% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1554259 RESOLVED Self Reported Incident Security Incident Opened 2019-05-24 · Closed 2023-02-22 · 96% similar
GlobalSign: SPKI lacks explicit NULL parameter,
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 94% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1579413 RESOLVED Self Reported Incident Opened 2019-09-06 · Closed 2022-11-14 · 93% similar
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action