GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign reported an incident involving the issuance of a certificate with an RSASSA-PSS public key, which was flagged by their post-issuance checks. The certificate was revoked shortly after its issuance. GlobalSign conducted an investigation to determine why their pre-issuance checks failed to prevent this certificate from being issued. They identified that a configuration issue in their validator settings allowed the certificate to be issued despite it not meeting compliance requirements. The CA has since updated its documentation and processes to prevent similar issues in the future, including implementing log shipping and monitoring tools to ensure proper validator configurations.
- GlobalSign issued a certificate with RSASSA-PSS public key.
- The certificate was revoked after being flagged by post-issuance checks.
- GlobalSign provided a full incident report detailing the investigation and corrective actions.
- GlobalSign confirmed that log shipping and configuration verification measures were successfully implemented.
- GlobalSign nv-sa — Initial incident report submitted regarding the issuance of a certificate with RSASSA-PSS public key.
- Community commenter — Inquired about the completion of a proper incident report.
- GlobalSign nv-sa — Submitted the full incident report detailing the investigation and corrective actions.
- Mozilla representative — Closed the ticket as completed/fixed.