GlobalSign: Invalid Common Names in Globalsign Certificates
The case was initiated by an external reporter who received multiple emails from the German postal service that used S/MIME certificates signed by GlobalSign. The reporter stated that the certificates may contain invalid common names (for example “noreply.packstation” and “BN”), and they reported the issue via GlobalSign’s Report Abuse page on 2017-09-05. GlobalSign confirmed it would investigate, but the reporter said the certificate was still valid and they did not receive further response beyond the initial confirmation. A Fastly participant noted that the certificates’ Extended Key Usage and issuer did not allow use for Server authentication (SSL/TLS), suggesting it was not a problem for TLS. Another participant agreed that, since the certificates were not trusted for TLS Web Server Authentication, it was not misissuance. The bug was ultimately resolved as INVALID.
- GlobalSign was contacted via its Report Abuse page about S/MIME certificates with potentially invalid common names.
- Mozilla CA Program bug 1425478 was filed regarding the reported invalid common names in GlobalSign-issued certificates.
- Flanga representative — Reported that they received S/MIME-signed emails whose GlobalSign certificates may have invalid common names and described GlobalSign’s initial investigation confirmation.
- Fastly representative — Noted the certificates’ Extended Key Usage does not allow Server authentication (SSL/TLS), indicating it likely was not a TLS problem.
- Titanous representative — Agreed that because the certificates are not trusted for TLS Web Server Authentication, it is not misissuance.