← GlobalSign nv-sa cases
Bugzilla #1420766 Certificate Misissuance

Globalsign / AlphaSSL: CAA mis-issuance on mixed wildcard/non-wildcard SAN

RESOLVED INVALID GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns an AlphaSSL certificate issued by GlobalSign that includes a mixed wildcard and non-wildcard DNS SAN ("*.invinsec.com" and "invinsec.com"). The reporter alleged that GlobalSign likely mis-issued because CAA was validated for the wildcard SAN but the base domain SAN was added without a further CAA check, and that the base domain was not permitted for GlobalSign at the time. GlobalSign’s CAA logs were provided, stating that at issuance time there were no issuewild entries and that "digicert.com", "globalsign.com", "letsencrypt.org", and "rapidssl.com" were listed as issue entries. The reporter responded that their DNS history was compiled from multiple scans at different times and argued the CAA configuration may have changed briefly, suggesting the issue could be a false positive. Mozilla’s Gerv resolved the bug as INVALID. No further remediation steps are described in the thread.

Model: gpt-5.4-nano Generated: 2026-06-13 17:40 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.86 7 comments
Chronology
  1. GlobalSign (AlphaSSL) issued a certificate for *.invinsec.com and invinsec.com.
  2. The bug was filed alleging CAA mis-issuance for the mixed wildcard/non-wildcard SAN.
  3. GlobalSign provided CAA log details and the reporter replied with scan-timestamp evidence; Mozilla resolved the bug as INVALID.
Thread Activity
  1. Scheitle representative — Filed the bug alleging GlobalSign likely mis-issued by validating CAA for the wildcard SAN but adding the base domain SAN without a further CAA check, and provided the certificate and related discussion links.
  2. Mozilla representative — Assigned the bug to the GlobalSign representative.
  3. Community commenter — Asked how the DNS history was created because GlobalSign’s CAA logs showed no issuewild entries and listed multiple issuers as issue entries.
  4. Scheitle representative — Explained the DNS history was compiled from multiple scans at different times and argued the CAA configuration may have changed briefly, making the report potentially a false positive.
  5. Mozilla representative — Resolved the bug as INVALID.
Participants
Scheitle representative Mozilla representative GlobalSign nv-sa Community commenter Bmo representative
Similar Local Cases
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 100% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1536760 RESOLVED Certificate Misissuance Opened 2019-03-20 · Closed 2023-02-22 · 85% similar
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 82% similar
SHA-1 issuance by GlobalSign root
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 79% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 79% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 79% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1301545 RESOLVED Certificate Misissuance Opened 2016-09-08 · Closed 2022-11-14 · 79% similar
GlobalSign CloudSSL CA - SHA256 - G3 issued certificate without required extensions
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 79% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action