← GlobalSign nv-sa cases
Bugzilla #1649937 Self Reported Incident

GlobalSign incident: OCSP Delegated Responder certificates missing id-pkix-ocsp-nocheck

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign disclosed that it had issued one or more OCSP Delegated Responder certificates without the required id-pkix-ocsp-nocheck response. The report was originally raised on mozilla.dev.security.policy and then tracked in Bugzilla by Mozilla and GlobalSign. GlobalSign said it investigated the issue, stopped including the OCSP Signing EKU in newly generated issuing CAs, and began revoking affected CA certificates in batches. The thread records multiple revocation and key-destruction actions through 2020 and 2021, along with an ISAE3000 report covering the non-performance of OCSP signing for the affected CAs. GlobalSign stated in January 2022 that the attached ISAE3000 Type II report concluded its remedial activities and that the incident could now be closed.

Model: gpt-5.4-mini Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.97 48 comments
Chronology
  1. Security issue involving OCSP Signing EKU in some issuing CAs was disclosed on mozilla.dev.security.policy.
  2. First batch of affected issuing CAs was revoked.
  3. Trusted Root hierarchies were revoked after a 72-hour postponement.
  4. Another batch of affected issuing CAs was revoked and some keys were destroyed.
  5. Additional affected CAs were revoked.
  6. Further affected CAs were revoked.
  7. Final remaining CAs in the plan were due to be revoked or destroyed.
  8. GlobalSign attached an ISAE3000 Type II report and said the incident could be closed.
Thread Activity
  1. Community commenter — Ryan Sleevi reported that GlobalSign had issued OCSP Delegated Responders without id-pkix-ocsp-nocheck and cited an example certificate.
  2. GlobalSign nv-sa — GlobalSign confirmed receipt of the report and said it was investigating.
  3. GlobalSign nv-sa — GlobalSign said it recognized the security issue, was working on a remediation plan, and would share an initial plan in Bugzilla.
  4. GlobalSign nv-sa — GlobalSign reported the first revocation batch and said it planned to revoke additional CAs.
  5. GlobalSign nv-sa — GlobalSign posted a detailed incident timeline, said it had ceased including the OCSP Signing EKU in newly generated issuing CAs, and described its remediation and audit plans.
  6. Mozilla representative — Ben Wilson set the matter for a report-back update on or before 15-Oct-2020.
  7. GlobalSign nv-sa — GlobalSign corrected one revocation date and said it would post a new overview after the July 28 activities.
  8. Mozilla representative — Ben Wilson said revoked and CCADB-updated CA certificates would be automatically added to OneCRL and asked GlobalSign to separate TLS-capable from non-TLS-capable issuers for the remaining entries.
  9. GlobalSign nv-sa — GlobalSign listed more revoked CAs and said backup copies of keys would be destroyed in the upcoming two weeks.
  10. Mozilla representative — Ben Wilson said the bug could probably be closed and progress tracked in Bug 1651447.
  11. GlobalSign nv-sa — GlobalSign asked to keep this bug open for customer communication and said it would use Bug 1651447 for the 7-day revocation tracking.
  12. GlobalSign nv-sa — GlobalSign said the last remaining CA had been actioned and that audit reporting was ongoing.
  13. GlobalSign nv-sa — GlobalSign attached the final ISAE3000 Type II report and said the remedial activities were concluded.
Participants
Community commenter GlobalSign nv-sa Mozilla representative Joeshaw representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 100% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid countryName
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1714968 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
GlobalSign: Incorrect RegNumber-Org Type combination
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 100% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 100% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1694460 RESOLVED Self Reported Incident Opened 2021-02-23 · Closed 2022-11-14 · 96% similar
GlobalSign: Issuing CA certificate with wrong notBefore date
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 96% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action