← GlobalSign nv-sa cases
Bugzilla #1575880
Certificate Problem Report
GlobalSign: SSL Certificates with US country code and invalid State/Prov
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign was notified of two SSL certificates containing invalid state information in the stateOrProvinceName field. Following a swift investigation, GlobalSign identified 31 certificates with similar issues and initiated revocation procedures. The certificates were revoked by August 28, 2019, and GlobalSign implemented additional flagging and review processes to prevent future occurrences. The company has committed to enhancing its validation procedures and has begun categorizing synonymous values for various jurisdictions to improve compliance.
Chronology
- GlobalSign notified of invalid state information in two SSL certificates.
- Certificates were revoked.
- All identified misissued certificates were revoked.
Participants
douglas.beattie@gmail.com
ryan.sleevi@gmail.com
wthayer@fastly.com
eva.vansteenberge@globalsign.com
External References
Similar Local Cases
GlobalSign: SPKI lacks explicit NULL parameter,
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
GlobalSign: EV TLS certificate with only metadata in JOI State field
GlobalSign: OCSP Status HTTP 530
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
GDCA: Insufficient Serial Number Entropy
GlobalSign: Incorrect Jurisdiction of Incorporation information for Japan