← GlobalSign nv-sa cases
Bugzilla #1605372 Certificate Problem Report

GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request

RESOLVED FIXED GlobalSign nv-sa
AI Summary

GlobalSign identified an issue where their OCSP responders were incorrectly responding with signatures from a default CA when presented with an invalid issuer. The problem was first reported by Microsoft after a security researcher raised concerns. GlobalSign implemented a workaround by disabling the default OCSP signer, ensuring that unauthorized responses were returned instead. All remediation steps were completed by January 2020, and no non-compliant certificates were issued during the incident.

Model: gpt-4o-mini Generated: 2026-06-13 21:02 UTC Confidence: 1.00
Chronology
  1. Microsoft informed GlobalSign of the OCSP issue.
  2. Workaround implemented on first OCSP cluster.
  3. Workaround scheduled for completion on other clusters.
  4. All remediation steps confirmed complete.
Participants
Paul Brown Wayne Thayer Ryan Sleevi Julio Montano
Similar Local Cases
#1625445 RESOLVED Certificate Problem Report Opened 2020-03-27 · Closed 2023-02-22 · 72% similar
GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days
#1667944 RESOLVED Certificate Problem Report Opened 2020-09-29 · Closed 2023-02-22 · 67% similar
GlobalSign: Empty SingleExtension in OCSP responses
#1630870 RESOLVED Certificate Problem Report Opened 2020-04-17 · Closed 2023-02-22 · 65% similar
GlobalSign: Certificate issued with RSASSA-PSS public key
#1598390 RESOLVED Certificate Problem Report Opened 2019-11-21 · Closed 2024-05-09 · 63% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
#1604124 RESOLVED Certificate Problem Report Opened 2019-12-16 · Closed 2023-02-22 · 62% similar
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
#1654896 RESOLVED Certificate Problem Report Opened 2020-07-23 · Closed 2023-02-22 · 60% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1524877 RESOLVED Certificate Problem Report Opened 2019-02-03 · Closed 2023-02-22 · 59% similar
GlobalSign: IP in dnsName
#1744518 RESOLVED Certificate Problem Report Opened 2021-12-06 · Closed 2023-02-22 · 58% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action