← GlobalSign nv-sa cases
Bugzilla #1591005 Certificate Problem Report

GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report

RESOLVED FIXED GlobalSign nv-sa
AI Summary

GlobalSign identified that 30 Intermediate Certificate Authorities (ICAs) were listed in the WebTrust CA audit report but not in the WebTrust Baseline Requirements (WTBR) report. These ICAs, while technically capable of TLS issuance due to the absence of Extended Key Usage (EKU) extensions, were not intended for such use and had not issued TLS certificates. The oversight was attributed to a misunderstanding of Mozilla's policy regarding the technical capabilities of ICAs. GlobalSign has since taken steps to revoke the affected ICAs and amend the audit reports accordingly.

Model: gpt-4o-mini Generated: 2026-06-13 20:03 UTC Confidence: 0.95
Chronology
  1. Discovery of 30 ICA certificates not listed in WTBR report.
  2. Revocation of three ICAs.
  3. Revocation of additional ICAs.
  4. Final key destruction of affected CA.
Participants
Arvid Vermote Ryan Sleevi Kathleen Wilson
External References
Similar Local Cases
#1599788 RESOLVED Certificate Problem Report Opened 2019-11-27 · Closed 2023-02-22 · 68% similar
GlobalSign: Failure to revoke noncompliant ICA within 7 days
#1393557 RESOLVED Certificate Problem Report Opened 2017-08-24 · Closed 2023-02-22 · 68% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1668007 RESOLVED Certificate Problem Report Opened 2020-09-29 · Closed 2023-02-22 · 67% similar
GlobalSign: Invalid stateOrProvinceName value
#1390997 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 67% similar
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
#1708834 RESOLVED Certificate Problem Report Opened 2021-04-30 · Closed 2023-02-22 · 66% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1654545 RESOLVED Certificate Problem Report Opened 2020-07-22 · Closed 2023-02-22 · 66% similar
GlobalSign: Failure to revoke noncompliant certificates within 5 days
#1651447 RESOLVED Certificate Problem Report Opened 2020-07-08 · Closed 2023-02-22 · 66% similar
GlobalSign: Failure to revoke noncompliant ICA within 7 days
#1649937 RESOLVED Certificate Problem Report Opened 2020-07-02 · Closed 2023-02-22 · 66% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action