← GlobalSign nv-sa cases
Bugzilla #1623356
Certificate Misissuance
GlobalSign: Misissuance of QWAC Certificates
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign reported the misissuance of four QWAC certificates, three of which were found to be non-compliant. Issues included improper content in the Organization Identifier and missing required extensions. The CA has temporarily halted the issuance of QWAC certificates until validation agents are retrained and system patches are applied. A comprehensive incident report was created, detailing the timeline of events and corrective actions taken, including the implementation of a new internal format validator to prevent future occurrences.
Chronology
- First non-compliant certificate issued
- First non-compliant certificate revoked
- Second non-compliant certificate issued
- Second non-compliant certificate revoked
- Third non-compliant certificate issued
- Third non-compliant certificate revoked
- Internal format validator created
Participants
douglas.beattie@gmail.com
ryan.sleevi@gmail.com
eva.vansteenberge@globalsign.com
bwilson@mozilla.com
External References
Similar Local Cases
GlobalSign: 4 Misissued certificates with invalid CN
GlobalSign: AT&T SSL certificates without the AIA extension
Sectigo: Subject field with unvalidated information included in certificates
SSL.com: Wildcard DV certificate issued with a non-validated domain name
GDCA: Incorrect Value in organizationName Field
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
Telekom Security: Certificate with invalid FQDN