← GlobalSign nv-sa cases
Bugzilla #1579413 Self Reported Incident

GlobalSign: OCSP responder returns invalid values for some precertificates

RESOLVED INVALID GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported an issue affecting OCSP responses for some precertificates that do not have corresponding certificates. The reporter said that, based on announcements by DigiCert and Let’s Encrypt, GlobalSign found that its precertificates without corresponding certificates return Unauthorized or Unknown. GlobalSign stated it was working with PrimeKey on a patch and updating its OCSP services to return proper values. GlobalSign also explained that Mozilla’s requirement is that certificates must not include cRLDistributionPoints or OCSP authorityInfoAccess extensions unless operational CRL or OCSP services exist, and that precertificates are treated as certificates for this purpose. In a later status update, GlobalSign said PrimeKey opened a ticket to resolve the issue in the November time frame in EJBCA 7.3.1, and that GlobalSign opened tickets for its OCSP service to store precertificates in its main certificate database so they are treated the same as certificates for OCSP handling. The incident was ultimately resolved as INVALID by the Mozilla participant, referencing a discussion on the mozilla.dev.security.policy mailing list.

Model: gpt-5.4-nano Generated: 2026-06-13 19:34 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.86 6 comments
Chronology
  1. GlobalSign identified that OCSP responses for some precertificates without corresponding certificates returned Unauthorized or Unknown and initiated remediation work with PrimeKey and its OCSP services.
  2. GlobalSign reported ongoing remediation steps, including a PrimeKey ticket for an EJBCA fix and OCSP service changes to store precertificates for proper OCSP responses.
  3. Mozilla resolved the incident report as INVALID after discussion on the mozilla.dev.security.policy mailing list.
Thread Activity
  1. Community commenter — Doug reported that GlobalSign precertificates without corresponding certificates return Unauthorized or Unknown via OCSP and said GlobalSign was working with PrimeKey on a patch and updating its OCSP services.
  2. Community commenter — Ryan asked whether the report was meant to be the full incident report and requested a timeline for further updates if more details were planned.
  3. Community commenter — Doug said GlobalSign would provide regular updates and complete an incident report, and explained the core problem as Mozilla’s requirement for operational CRL/OCSP services for extensions present on precertificates.
  4. Community commenter — Ryan requested weekly updates and a complete remediation timeline.
  5. Community commenter — Doug provided a status update: PrimeKey opened a ticket for an EJBCA 7.3.1 fix in November, and GlobalSign opened tickets to modify its OCSP service to store precertificates in the main certificate database for proper OCSP responses.
  6. Fastly representative — Wthayer thanked for the incident report and resolved the incident as INVALID, citing the outcome of discussion on the mozilla.dev.security.policy list.
Participants
Community commenter Fastly representative
Similar Local Cases
#1552586 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 100% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1554259 RESOLVED Self Reported Incident Security Incident Opened 2019-05-24 · Closed 2023-02-22 · 100% similar
GlobalSign: SPKI lacks explicit NULL parameter,
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 100% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1599775 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-27 · Closed 2023-02-22 · 94% similar
GlobalSign: Wrong business category (Non Commercial Entity when should have been Private Organization)
#1393555 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 93% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 93% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1649937 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 87% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 86% similar
GlobalSign: Invalid stateOrProvinceName and locality pair

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action