GlobalSign: Untimely revocation of TLS certificate after submission of private key compromise
GlobalSign reported an incident involving untimely revocation of a TLS certificate after it received a certificate problem report alleging private key compromise. The CA said it became aware of the issue on 2020-03-08 when a compliance employee was reviewing open certificate problem reports, and noted that the report submitted on 2020-03-06 21:48 GMT was flagged for more information even though it contained sufficient evidence (a CSR with unique information referencing the compromise). GlobalSign stated that because revocation did not happen within 24 hours, the certificate problem report was not handled in line with Baseline Requirements section #4.9.1.1. After internal review, GlobalSign issued instructions for revocation and revoked the corresponding certificate (crt.sh ID https://crt.sh/?id=2522275549) on 2020-03-08 20:12:32 GMT. GlobalSign also described process changes, including requiring immediate escalation of future private key compromise reports to the compliance team, with the process change expected to be completed by 2020-03-20. In later discussion, GlobalSign explained accepted evidence methods for technical support agents and described additional monitoring via its 24/7 Security / Compliance Operations Center, and another participant stated that remediation appeared complete.
- GlobalSign received a certificate problem report alleging private key compromise for a TLS certificate.
- GlobalSign identified an error in handling the private key compromise report and revoked the affected certificate.
- GlobalSign expected completion of process changes requiring escalation of private key compromise reports to the compliance team.
- GlobalSign nv-sa — GlobalSign submitted a preliminary incident report, stating the initial evidence was later determined sufficient and the certificate was revoked on 2020-03-08.
- GlobalSign nv-sa — GlobalSign provided a detailed timeline and explained that revocation did not occur within 24 hours due to handling/decision-tree issues, and described remediation steps and an expected completion date of 2020-03-20.
- Community commenter — Ryan asked what evidence methods were accepted and where that information is found, and requested details on other incidents and mitigation evaluation.
- GlobalSign nv-sa — Arvid listed accepted evidence methods (private key, signed message, or links/evidence of compromise) and described that escalation to compliance for unknown evidence was not formally required; he also described SOC monitoring and planned process changes.
- Community commenter — Ryan noted the response’s similarity to concerns raised in another Entrust-related bug and asked for careful consideration.
- GlobalSign nv-sa — Arvid explained why compliance employees are not the first line for processing and described reliance on technical support and the 24/7 Security / Compliance Operations Center for filtering/escalation.
- Fastly representative — wthayer stated it appears that all questions have been answered and remediation is complete.