← GlobalSign nv-sa cases
Bugzilla #1552586
Self Reported Incident
Certificate Misissuance
GlobalSign: 4 Misissued certificates with invalid CN
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GlobalSign reported a compliance issue involving four misissued SSL certificates with invalid Common Names (CN). The CA became aware of the problem through its post-issuance compliance checker on May 17, 2019. Following the detection, GlobalSign promptly revoked the certificates and initiated an investigation. The root cause was identified as a missing check for CN/SAN validation in a specific scenario involving a deprecated API. GlobalSign has since implemented code updates to ensure proper validation and is conducting a thorough review of its systems to prevent future occurrences.
Chronology
- GlobalSign detected misissued certificates through its compliance checker.
- Certificates were revoked and an investigation was initiated.
- GlobalSign identified the root cause related to a missing validation check.
- GlobalSign implemented updates to ensure proper validation checks.
Thread Activity
- Community commenter — GlobalSign's compliance checker alerted us to the problem in 4 SSL certificates.
- Community commenter — We rolled out updated code that now properly checks the CN and SAN values.
- Community commenter — We verified that all proper checks are in place for AEG certificate requests.
- Fastly representative — It appears that all questions have been answered and remediation is complete.
Participants
Community commenter
Fastly representative
External References
Similar Local Cases
GlobalSign: Invalid countryName
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: IP in dnsName
GlobalSign: AT&T SSL certificates without the AIA extension
GlobalSign: SPKI lacks explicit NULL parameter,
GlobalSign: SSL Certificates with US country code and invalid State/Prov
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates
GlobalSign: Wrong business category (Non Commercial Entity when should have been Private Organization)