GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days
This case concerns GlobalSign certificates that were not revoked within the required 5-day timeframe. GlobalSign said it became aware of the issue while preparing a report for mis-issuance of two QWAC certificates, noticing that the certificates had not been revoked within 5 days. GlobalSign described that certificate #1 and certificate #2 were issued on Mar 13 and Mar 14, 2020, respectively, and that revocation requests were made to support on Mar 13/14 but were not acted upon until Monday Mar 16 due to system issues and load on support. GlobalSign stated that the support agents created revocation requests with a 5-day maximum to-be-invoked-by date that was outside the permitted timeline, and that compliance verified ticket creation but did not notice the incorrect revocation window start time. GlobalSign’s remediation included changing internal handling so that revocation requests from internal sources trigger its 24/7 Security/Compliance Operations Center and that such requests include a specific start/end date/time for the revocation window starting at observation of the mis-issuance. The bug was marked RESOLVED with resolution FIXED, and a later comment stated that remediation was complete.
- GlobalSign issued QWAC certificate #1.
- GlobalSign issued QWAC certificate #2.
- GlobalSign revoked both QWAC certificates.
- GlobalSign nv-sa — Paul Brown explained that GlobalSign noticed the two QWACs were not revoked within 5 days, provided issuance/revocation dates and CT links, described the cause (revocation window start time mishandled due to system issues and support/compliance process gaps), and outlined remediation including 24/7 SOC triggering and explicit revocation window start/end times.
- Community commenter — Ryan Sleevi asked which revocation requests would not trigger the 24/7 monitoring.
- GlobalSign nv-sa — Paul Brown replied that external sources not reporting via the appropriate channels would not trigger 24/7 monitoring until redirected, and gave examples such as customers requesting revocation via email to sales representatives.
- Community commenter — Ryan Sleevi asked how the deadline timer would be calculated in an edge case where a customer requests revocation to a sales representative and the internal ticket is filed later.
- GlobalSign nv-sa — Paul Brown said GlobalSign attempts to use the original time of receiving as the clock start, but noted verification and authorization checks could add delay (describing a 2+X+ASAP style timeline).
- Community commenter — Ryan Sleevi stated the explanation clarified edge cases and how the changes address the root cause.
- Fastly representative — Wayne Thayer indicated that remediation was complete.