← GlobalSign nv-sa cases
Bugzilla #1524877
Certificate Problem Report
GlobalSign: IP in dnsName
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign issued certificates with invalid dnsNames containing IP addresses, ceasing this practice in 2016 without revoking the affected certificates. An incident report was requested due to their failure to respond to a problem report within the required timeframe. Following discussions, all identified certificates were eventually revoked, and GlobalSign has since updated their processes to ensure timely responses to future reports.
Chronology
- Problem report sent to GlobalSign
- All identified certificates revoked
- GlobalSign updated their report-abuse process
Participants
Jonathan Rudenberg
Douglas Beattie
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
GlobalSign: Failure to revoke noncompliant ICA within 7 days
Sectigo: invalid dnsName
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report