← GlobalSign nv-sa cases
Bugzilla #1649937
Certificate Problem Report
GlobalSign: Incorrect OCSP Delegated Responder Certificate
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign issued OCSP Delegated Responder certificates without including the required 'id-pkix-ocsp-nocheck' response, violating Baseline Requirements. The issue was reported on July 1, 2020, leading to an investigation and a remediation plan that included revoking affected certificates. GlobalSign successfully revoked multiple CA certificates and destroyed the associated keys. An ISAE3000 report was later provided, confirming the non-performance of OCSP signing by the affected CAs. The case is now resolved.
Chronology
- Security issue disclosed on mozilla.dev.security.policy
- First batch of revocations of affected issuing CA
- Active key pairs of affected CA destroyed
- ISAE3000 report regarding non-performance of OCSP signing submitted
Participants
Ryan Sleevi
Arvid Vermote
Douglas Beattie
External References
Similar Local Cases
GlobalSign: Invalid stateOrProvinceName value
GlobalSign: Failure to revoke noncompliant certificates within 5 days
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: IP in dnsName
GlobalSign: Failure to revoke noncompliant ICA within 7 days