GlobalSign audit scope omission and delayed revocation for 30 ICAs without EKU
GlobalSign opened this case after reviewing its CCADB task for failed Audit Letter Validation results and finding 30 intermediate CA certificates without EKU extensions that were technically capable of TLS issuance but were not included in its SSLBR and EVSSL audit reports. GlobalSign said the ICAs were older, were disclosed in CCADB, and had not issued TLS server certificates, but Mozilla questioned the audit-scope explanation and asked for revocation timelines. GlobalSign later said it would revoke or otherwise remediate the affected ICAs in stages, including adding some certificates to OneCRL, revoking others, and destroying keys for timestamping CAs. Over time, GlobalSign reported multiple revocation and key-destruction actions, attached updated audit and destruction reports, and stated that all affected CAs had been revoked or otherwise addressed. Mozilla indicated the bug could be used for both the initial BR compliance issue and the delayed revocation issue, and the case was later scheduled for closure.
- GlobalSign found 30 intermediate CA certificates without EKU that were omitted from its BR audit report coverage.
- GlobalSign revoked three affected ICAs and requested the affected intermediates be added to OneCRL.
- GlobalSign revoked seven more affected ICAs.
- GlobalSign destroyed the active keypairs for two timestamping CAs.
- GlobalSign revoked the three PersonalSign G3 CAs.
- GlobalSign attached the final key-destruction report for the remaining CA and said remedial actions were complete.
- GlobalSign nv-sa — GlobalSign reported that 30 ICAs without EKUs were found during an internal review of ALV results and said they were missing from the SSLBR and EVSSL audit reports.
- Community commenter — Ryan Sleevi questioned the audit-scope explanation and raised concerns about the proposed remediation and Mozilla policy expectations.
- GlobalSign nv-sa — GlobalSign said three ICAs would be revoked on November 20, six were covered by a later audit period, and 21 would need replacement planning; it also said a separate incident report would be filed for missing revocation deadlines.
- Mozilla representative — Kathleen Wilson asked which intermediate certificates should be added to OneCRL.
- GlobalSign nv-sa — GlobalSign confirmed that all 30 attached intermediate certificates should be added to OneCRL.
- Mozilla representative — Mozilla said the bug could cover both the BR audit omission and delayed revocation, and that the delayed-revocation whiteboard tag should still be used.
- GlobalSign nv-sa — GlobalSign provided an updated remediation table showing revocations, audit coverage, and planned key destruction for the remaining affected ICAs.
- GlobalSign nv-sa — GlobalSign attached the ISAE3000 report for the destruction of the timestamping CA keys.
- Mozilla representative — Mozilla asked whether any remaining CA certificates still needed revocation.
- GlobalSign nv-sa — GlobalSign attached the final key-destruction report for the remaining CA and said the remedial actions were concluded.
- Mozilla representative — Mozilla said it would schedule the bug for closure on or about 2021-03-31.