← GlobalSign nv-sa cases
Bugzilla #1425478 Certificate Misissuance

GlobalSign: Invalid Common Names in Globalsign Certificates

RESOLVED INVALID GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case was initiated by an external reporter who received multiple emails from the German postal service that used S/MIME certificates signed by GlobalSign. The reporter stated that the certificates may contain invalid common names (for example “noreply.packstation” and “BN”), and they reported the issue via GlobalSign’s Report Abuse page on 2017-09-05. GlobalSign confirmed it would investigate, but the reporter said the certificate was still valid and they did not receive further response beyond the initial confirmation. A Fastly participant noted that the certificates’ Extended Key Usage and issuer did not allow use for Server authentication (SSL/TLS), suggesting it was not a problem for TLS. Another participant agreed that, since the certificates were not trusted for TLS Web Server Authentication, it was not misissuance. The bug was ultimately resolved as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 17:40 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.86 3 comments
Chronology
  1. GlobalSign was contacted via its Report Abuse page about S/MIME certificates with potentially invalid common names.
  2. Mozilla CA Program bug 1425478 was filed regarding the reported invalid common names in GlobalSign-issued certificates.
Thread Activity
  1. Flanga representative — Reported that they received S/MIME-signed emails whose GlobalSign certificates may have invalid common names and described GlobalSign’s initial investigation confirmation.
  2. Fastly representative — Noted the certificates’ Extended Key Usage does not allow Server authentication (SSL/TLS), indicating it likely was not a TLS problem.
  3. Titanous representative — Agreed that because the certificates are not trusted for TLS Web Server Authentication, it is not misissuance.
Participants
Flanga representative Fastly representative Titanous representative
Similar Local Cases
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 80% similar
GlobalSign: CRL contains invalid signature algorithm
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 78% similar
SHA-1 issuance by GlobalSign root
#1353833 RESOLVED Certificate Misissuance Validation Issue Opened 2017-04-05 · Closed 2023-02-22 · 78% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1524877 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 76% similar
GlobalSign: IP in dnsName
#1524878 RESOLVED Certificate Misissuance Duplicate Or Superseded Opened 2019-02-03 · Closed 2023-02-22 · 76% similar
Asseco DS / Certum: IP in dnsName
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 73% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 68% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1521623 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-01-21 · Closed 2024-05-09 · 68% similar
Amazon Trust Services: Failure to comply with RFC 5280

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action