← GlobalSign nv-sa cases
Bugzilla #1650018
Technical Compliance
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign identified issues with a cross certificate issued to Google that does not comply with the Baseline Requirements (BR) regarding Certificate Policy Object Identifiers. The certificate, issued on June 17, 2020, presents conflicts between including both Domain Validation (DV) and Organization Validation (OV) identifiers in the Subject field. GlobalSign raised this issue transparently, noting that the current BR language may not adequately address the requirements for Subordinate CA certificates. The matter has been resolved with acknowledgment of the need for clarifications in the BRs.
Chronology
- GlobalSign reports the issue with the cross certificate.
- Discussion on the interpretation of BR section 7.1.6.1.
- Intention to close the matter unless further issues arise.
Participants
Arvid Vermote
Brett Wilson
External References
Similar Local Cases
GoDaddy: DV certificates with organizationalUnit field in subject
GlobalSign: CRL contains invalid signature algorithm
Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution
Visa: Non-BR-Compliant OCSP Responders
Entrust: Non-BR-Compliant OCSP Responder
Consorci AOC: Non-BR-Compliant OCSP Responders
Certainly: Root CRL validity period exceeds maximum by one second
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved