GlobalSign: SPKI lacks explicit NULL parameter
GlobalSign identified a compliance issue involving eight unrevoked SSL certificates that lacked the required NULL parameter, violating RFC 3279. Upon notification via the mdsp mailing list, GlobalSign promptly revoked the affected certificates and initiated an investigation into the cause. They discovered that their backend CA platform, PrimeKey, did not properly handle the encoding of parameters. GlobalSign implemented a zlint check to prevent future occurrences and worked with PrimeKey to address the underlying software issue. The system was successfully patched on July 18, 2019, and all remediation steps have been completed.
- GlobalSign was alerted about the problematic certificates via the MSDP mailing list.
- GlobalSign revoked the certificates.
- GlobalSign released an updated zlint to block future issuance of certificates without the NULL parameter.
- The system was patched with the updated version of EJBCA.
- Community commenter — Reported the issue regarding the lack of NULL parameter in certificates.
- Community commenter — Explained the cause of the issue and the steps being taken to resolve it.
- Fastly representative — Requested a proper incident report from GlobalSign.
- Community commenter — Provided a detailed incident report outlining the timeline and actions taken.
- Fastly representative — Confirmed that all questions have been answered and remediation is complete.