GlobalSign incident report and remediation for invalid US state/province values in SSL certificates
GlobalSign reported that a third party notified it about two SSL certificates containing invalid US state information in the stateOrProvinceName or jurisdictionStateOrProvinceName fields. GlobalSign said it investigated those certificates within 24 hours, contacted the certificate owners, and revoked the two certificates on 2019-08-23. It then conducted a broader internal review and found 31 unique certificates with invalid values in those fields, with issuance dates ranging from October 2016 to July 2019. GlobalSign said it had stopped issuing certificates with this problem and added warning indicators and email alerts for validation staff. The thread then tracked a longer remediation effort to build jurisdiction-specific whitelists and approval controls, with GlobalSign reporting in January 2021 that all remaining jurisdictions had been added to the whitelist. Mozilla later indicated the matter could be closed.
- GlobalSign was notified about two SSL certificates with invalid US state information.
- The two initially reported certificates were revoked.
- GlobalSign reported 31 unique affected certificates and said it had stopped issuing certificates with the problem.
- GlobalSign said all remaining jurisdictions had been added to the whitelist.
- Community commenter — GlobalSign opened the bug and described the third-party report, the two affected certificates, and its initial investigation and replacement/revocation plan.
- Community commenter — GlobalSign said it had found 31 unique affected certificates, revoked the misissued certificates, and added warning indicators and email alerts for validation staff.
- GlobalSign nv-sa — GlobalSign said its preventative measures were initially limited to US address or jurisdiction information and outlined a plan to review additional countries.
- GlobalSign nv-sa — GlobalSign described a phased approval and whitelisting mechanism, with milestones through 2021, to prevent issuance with unapproved jurisdiction values.
- GlobalSign nv-sa — GlobalSign said it had added all remaining jurisdictions to the whitelist and that the whitelist was now running for all jurisdictions.
- Mozilla representative — Mozilla said the matter appeared ready to be closed.