← GlobalSign nv-sa cases
Bugzilla #1625445
Certificate Problem Report
GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign faced a compliance issue where two Qualified Website Authentication Certificates (QWACs) were not revoked within the required five-day period. The failure was attributed to system issues and miscommunication within the compliance and support teams. Both certificates were eventually revoked, but the incident highlighted the need for improved processes to ensure timely revocation in the future. GlobalSign has since implemented changes to trigger 24/7 monitoring for revocation requests and clarified the timeline for revocation actions.
Chronology
- Issued certificate #1
- Request to support to have certificate #1 revoked
- Issued certificate #2
- Request to support to have certificate #2 revoked
- Support created tickets requesting revocation for both certificates
- Both certificates revoked
Participants
Paul Brown
Ryan Sleevi
Wayne Thayer
External References
Similar Local Cases
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign: Empty SingleExtension in OCSP responses
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: Failure to revoke noncompliant certificates within 5 days
GlobalSign: IP in dnsName
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: Untimely revocation of TLS certificate after submission of private key compromise