← GlobalSign nv-sa cases
Bugzilla #1552586 Certificate Misissuance

GlobalSign: 4 Misissued certificates with invalid CN

RESOLVED FIXED GlobalSign nv-sa
AI Summary

GlobalSign identified and resolved an issue involving four misissued SSL certificates that contained invalid Common Names (CN). The problem was detected by their post-issuance compliance checker, which alerted them shortly after the certificates were issued. An investigation revealed that a deprecated API allowed invalid CN values to be used without proper validation. GlobalSign has since revoked the misissued certificates and is implementing changes to ensure that such issues do not recur, including disabling the deprecated API and enhancing their validation checks.

Model: gpt-4o-mini Generated: 2026-06-13 18:14 UTC Confidence: 0.95
Chronology
  1. Certificates issued
  2. Compliance checker detected misissued certificates
  3. Investigation started
  4. Certificates revoked
  5. Further analysis determined the cause of the issue
  6. Updated code rolled out to check CN and SAN values
  7. Responses to follow-up questions provided
  8. Remediation confirmed complete
Participants
douglas.beattie@gmail.com ryan.sleevi@gmail.com wthayer@fastly.com
External References
Similar Local Cases
#1547691 RESOLVED Certificate Misissuance Opened 2019-04-29 · Closed 2023-02-22 · 74% similar
GlobalSign: AT&T SSL certificates without the AIA extension
#1623356 RESOLVED Certificate Misissuance Opened 2020-03-18 · Closed 2023-02-22 · 65% similar
GlobalSign: Misissuance of QWAC Certificates
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 58% similar
Telia: Misissued certificate - Invalid wildcard format
#1612332 RESOLVED Certificate Misissuance Opened 2020-01-30 · Closed 2023-02-22 · 56% similar
Telia: Ambiguity on KeyUsage with ECC public key
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 51% similar
Telia: invalid IP value in SAN DNS field
#1048045 RESOLVED Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 51% similar
GlobalSign Partner: No SAN
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 50% similar
Sectigo: Subject field with unvalidated information included in certificates
#1443857 RESOLVED Certificate Misissuance Opened 2018-03-07 · Closed 2023-02-22 · 50% similar
Camerfirma: Non-BR-Compliant Issuance - DNSName is empty

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action