← GlobalSign nv-sa cases
Bugzilla #1620922
Certificate Problem Report
GlobalSign: Untimely revocation of TLS certificate after submission of private key compromise
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign faced an incident involving the untimely revocation of a TLS certificate following a report of private key compromise. The issue arose when the initial evidence submitted was not recognized as sufficient by the weekend duty staff, leading to delays in revocation. The certificate was ultimately revoked after further review confirmed the evidence was adequate. GlobalSign has since implemented changes to ensure that future reports of key compromise are escalated immediately to the compliance team to prevent similar issues.
Chronology
- Initial report of private key compromise submitted.
- Certificate revoked after further review.
- Process changes to escalate key compromise reports implemented.
Participants
Arvid Vermote
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Invalid stateOrProvinceName value
GlobalSign: Failure to revoke noncompliant certificates within 5 days
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: IP in dnsName
GlobalSign: Invalid countryName
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8