← GlobalSign nv-sa cases
Bugzilla #1536760 Certificate Misissuance

GlobalSign: Virginia Tech Insufficient Serial Number Entropy

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a technically constrained CA operated by Virginia Tech under GlobalSign that issued certificates with insufficient serial number entropy. The issue was triggered by a disclosure report received by GlobalSign, describing that certificates issued from 9/30/2016 through 4/26/2018 had serial numbers with the leading bit set to 0, resulting in 63-bit serial numbers instead of the expected at least 64 bits. GlobalSign investigated the issuance and stated that certificates issued prior to 1 August 2017 were not compliant, while certificates issued between 8/1/2017 and 4/26/2018 had sufficient serial number entropy. GlobalSign stated that Virginia Tech stopped issuing certificates on 4/26/2018 and that the CA expires on 12/9/2019. GlobalSign reported that it revoked mis-issued certificates, including a status update that 147 of 174 non-expired mis-issued certificates had been revoked, and later confirmed that all non-expired certificates with 63-bit serial numbers were successfully revoked. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:08 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.86 8 comments
Chronology
  1. Virginia Tech began issuing certificates with 63-bit serial numbers under the technically constrained CA operated via GlobalSign.
  2. GlobalSign reported that certificates issued on/after 1 August 2017 were compliant with sufficient serial number entropy (per its investigation).
  3. Virginia Tech stopped issuing certificates under the constrained CA.
  4. GlobalSign researched the Virginia Tech issuance based on the disclosure report and identified non-compliant certificates prior to 1 August 2017.
  5. GlobalSign reported revoking 147 of 174 non-expired mis-issued certificates.
  6. GlobalSign confirmed all non-expired certificates with 63-bit serial numbers were successfully revoked.
Thread Activity
  1. Community commenter — Reported that Virginia Tech issued serial numbers with leading bit set to 0 (63 bits) instead of the expected at least 64 bits during 9/30/2016–4/26/2018.
  2. Community commenter — Explained GlobalSign’s awareness via a disclosure report, provided investigation details, stated the CA stopped issuing on 4/26/2018, and described planned revocation timing.
  3. Community commenter — Created an attachment listing the misissued certificates.
  4. Community commenter — Asked for the events on 1 August 2017 that changed compliance and for details on supervision and why detection was delayed.
  5. Community commenter — Said Virginia Tech changed to 128-bit serial numbers on 1 August 2017 and that GlobalSign’s initial analysis did not include this CA because it had not been issuing since April 2018.
  6. Community commenter — Acknowledged Virginia Tech’s proactive change and left a needinfo while waiting for a revocation timetable/plan.
  7. Community commenter — Updated that Virginia Tech updated its EJBCA setting to 128 bits and reported revocation of 147 of 174 non-expired mis-issued certificates, requesting an extension for remaining service owners.
  8. Community commenter — Confirmed that all non-expired certificates with 63-bit serial numbers had been successfully revoked.
Participants
Community commenter
Similar Local Cases
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 96% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 90% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 88% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 88% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1420766 RESOLVED Certificate Misissuance Opened 2017-11-26 · Closed 2024-05-09 · 85% similar
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 82% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 81% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 81% similar
GlobalSign Partner: No SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action