← GlobalSign nv-sa cases
Bugzilla #1605372 Certificate Misissuance

GlobalSign: OCSP responders responded with the default CA signer when an invalid issuer was provided

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports an OCSP responder behavior issue affecting GlobalSign’s OCSP infrastructure. Paul Brown stated that Microsoft informed GlobalSign of an issue with Microsoft’s OCSP responder that had been reported by a security researcher, and GlobalSign identified the issue on its OCSP cluster. GlobalSign linked the issue to an EJBCA problem (ECA-8620) and stated that no non-compliant certificates were issued. As remediation, GlobalSign disabled the default OCSP signer so that the system would respond with “Unauthorized (unsigned)” rather than an unknown signed response from a default signer, and then updated production OCSP clusters with the workaround. In a later update, GlobalSign stated that remediation steps were completed by removing the default responders and that new CA Certificate Compliance Bugzilla tickets now automatically create SOC incident-management tickets that must be investigated and signed off by the relevant team. The bug was marked RESOLVED with resolution FIXED, and Microsoft later noted that Bug 1620727 was marked as a duplicate of this bug.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.50 8 comments
Chronology
  1. Microsoft informed GlobalSign of an OCSP responder issue reported by a security researcher; GlobalSign identified the issue on its OCSP cluster later that day.
  2. GlobalSign matched the issue to EJBCA issue ECA-8620 and noted a fix was on staging but not ready for production.
  3. GlobalSign identified a workaround and updated the first production OCSP cluster with it.
  4. GlobalSign scheduled updates of other OCSP clusters to complete the workaround rollout.
  5. GlobalSign confirmed remediation was complete and described SOC incident-management integration for future CA Certificate Compliance tickets.
  6. Microsoft indicated Bug 1620727 was marked as a duplicate of this bug.
Thread Activity
  1. GlobalSign nv-sa — Paul Brown provided an incident report describing how GlobalSign became aware of the OCSP issue, the timeline of investigation and remediation, and stated that no non-compliant certificates were issued.
  2. Fastly representative — Wayne Thayer asked clarifying questions about the Microsoft notification, the workaround, and whether Primekey notified customers.
  3. Community commenter — Ryan Sleevi asked which OCSP responders were affected to map scope and impact.
  4. GlobalSign nv-sa — Paul Brown clarified that a security researcher informed Microsoft, Microsoft informed GlobalSign, described the workaround (disabling the default OCSP signer), and stated that for TLS only Microsoft and GlobalSign OCSP responders were affected.
  5. Fastly representative — Wayne Thayer asked Paul to confirm that all remediation steps had been completed.
  6. GlobalSign nv-sa — Paul Brown confirmed remediation was complete (default responders removed) and stated that new CA Certificate Compliance Bugzilla tickets now automatically create SOC incident-management tickets for investigation and sign-off.
  7. Fastly representative — Wayne Thayer stated it appeared all questions were answered and remediation was complete.
  8. Microsoft Corporation — Julio Montano noted that Bug 1620727 was marked as a duplicate of this bug.
Participants
GlobalSign nv-sa Fastly representative Community commenter Microsoft Corporation
Related Bugzilla IDs Mentioned
Similar Local Cases
#1536760 RESOLVED Certificate Misissuance Opened 2019-03-20 · Closed 2023-02-22 · 61% similar
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
#1304089 RESOLVED Certificate Misissuance Opened 2016-09-20 · Closed 2022-11-14 · 60% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 54% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 54% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 53% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 53% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1420766 RESOLVED Certificate Misissuance Opened 2017-11-26 · Closed 2024-05-09 · 52% similar
Globalsign / AlphaSSL: CAA Mis-Issuance on mix of wildcard and non-wildcard DNS names in SAN
#1579413 RESOLVED Self Reported Incident Opened 2019-09-06 · Closed 2022-11-14 · 50% similar
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action