← GlobalSign nv-sa cases
Bugzilla #1591005 Delayed Revocation

GlobalSign audit scope omission and delayed revocation for 30 ICAs without EKU

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign opened this case after reviewing its CCADB task for failed Audit Letter Validation results and finding 30 intermediate CA certificates without EKU extensions that were technically capable of TLS issuance but were not included in its SSLBR and EVSSL audit reports. GlobalSign said the ICAs were older, were disclosed in CCADB, and had not issued TLS server certificates, but Mozilla questioned the audit-scope explanation and asked for revocation timelines. GlobalSign later said it would revoke or otherwise remediate the affected ICAs in stages, including adding some certificates to OneCRL, revoking others, and destroying keys for timestamping CAs. Over time, GlobalSign reported multiple revocation and key-destruction actions, attached updated audit and destruction reports, and stated that all affected CAs had been revoked or otherwise addressed. Mozilla indicated the bug could be used for both the initial BR compliance issue and the delayed revocation issue, and the case was later scheduled for closure.

Model: gpt-5.4-mini Generated: 2026-06-13 20:03 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.93 50 comments
Chronology
  1. GlobalSign found 30 intermediate CA certificates without EKU that were omitted from its BR audit report coverage.
  2. GlobalSign revoked three affected ICAs and requested the affected intermediates be added to OneCRL.
  3. GlobalSign revoked seven more affected ICAs.
  4. GlobalSign destroyed the active keypairs for two timestamping CAs.
  5. GlobalSign revoked the three PersonalSign G3 CAs.
  6. GlobalSign attached the final key-destruction report for the remaining CA and said remedial actions were complete.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign reported that 30 ICAs without EKUs were found during an internal review of ALV results and said they were missing from the SSLBR and EVSSL audit reports.
  2. Community commenter — Ryan Sleevi questioned the audit-scope explanation and raised concerns about the proposed remediation and Mozilla policy expectations.
  3. GlobalSign nv-sa — GlobalSign said three ICAs would be revoked on November 20, six were covered by a later audit period, and 21 would need replacement planning; it also said a separate incident report would be filed for missing revocation deadlines.
  4. Mozilla representative — Kathleen Wilson asked which intermediate certificates should be added to OneCRL.
  5. GlobalSign nv-sa — GlobalSign confirmed that all 30 attached intermediate certificates should be added to OneCRL.
  6. Mozilla representative — Mozilla said the bug could cover both the BR audit omission and delayed revocation, and that the delayed-revocation whiteboard tag should still be used.
  7. GlobalSign nv-sa — GlobalSign provided an updated remediation table showing revocations, audit coverage, and planned key destruction for the remaining affected ICAs.
  8. GlobalSign nv-sa — GlobalSign attached the ISAE3000 report for the destruction of the timestamping CA keys.
  9. Mozilla representative — Mozilla asked whether any remaining CA certificates still needed revocation.
  10. GlobalSign nv-sa — GlobalSign attached the final key-destruction report for the remaining CA and said the remedial actions were concluded.
  11. Mozilla representative — Mozilla said it would schedule the bug for closure on or about 2021-03-31.
Participants
GlobalSign nv-sa Community commenter Mozilla representative Fastly representative
Similar Local Cases
#1599788 RESOLVED Delayed Revocation Opened 2019-11-27 · Closed 2023-02-22 · 100% similar
GlobalSign: Failure to revoke noncompliant ICA within 7 days
#1620922 RESOLVED Delayed Revocation Opened 2020-03-09 · Closed 2023-02-22 · 100% similar
GlobalSign: Untimely revocation of TLS certificate after submission of private key compromise
#1651447 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 100% similar
GlobalSign: Failure to revoke noncompliant ICA within 7 days
#1625445 RESOLVED Delayed Revocation Opened 2020-03-27 · Closed 2023-02-22 · 95% similar
GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days
#1639799 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 94% similar
GlobalSign: Failure to revoke key-compromised certificate within 24 hours
#1613406 RESOLVED Delayed Revocation Opened 2020-02-05 · Closed 2023-02-22 · 81% similar
SwissSign: Delayed revocation for mispellings in Location for a number of Certificates
#1942879 RESOLVED Delayed Revocation Opened 2025-01-21 · Closed 2025-02-12 · 79% similar
Globalsign: Delayed revocation
#1614449 RESOLVED Delayed Revocation Opened 2020-02-10 · Closed 2024-06-30 · 78% similar
SK ID Solutions: ALV failures on intermediate certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action