GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs
GlobalSign reported an incident involving a cross certificate it created under a contract with Google, intended to allow Google to issue BR-compliant OV and DV leaf certificates and certain other certificate types. GlobalSign said it discovered issues while populating the Certificate Policies extension for this cross certificate in a BR-compliant manner, and it noted that the cross certificate was issued on June 17, 2020 and does not comply with CABF Baseline Requirements section 7.1.6.1. GlobalSign also stated that, upon investigation of issued subordinate CAs, it found four other CA certificates that include policy identifier 2.23.140.1.2.1 and organizationName in the Subject. In the thread, Mozilla’s representative discussed an interpretation of BR section 7.1.6.1 that would allow use of both policy identifiers (OV and DV) in the same subordinate CA, and suggested clarifying the provision with the CA/Browser Forum. GlobalSign stated it endorsed a CABForum draft ballot (“Cleanups and Clarifications”) intended to clarify section 7.1.6.1 and referenced a GitHub commit for the draft updates. The bug was resolved as FIXED, and Mozilla indicated an intention to close the matter on or about 14-Sept-2020 unless other issues were raised.
- GlobalSign issued the cross certificate from GlobalSign Root R1 to the Google GTS Root R1.
- GlobalSign opened a CA Program bug reporting the cross certificate’s non-compliance with CABF Baseline Requirements section 7.1.6.1.
- Mozilla discussed an interpretation of BR section 7.1.6.1 and the need for clarification.
- GlobalSign endorsed a CABForum draft ballot to clarify BR section 7.1.6.1.
- Mozilla indicated it intended to close the matter around 14-Sept-2020 unless new issues were raised.
- The bug was marked RESOLVED (FIXED).
- GlobalSign nv-sa — GlobalSign described the Google cross-certificate arrangement, said it discovered issues populating Certificate Policies in a BR-compliant manner, and reported that the cross certificate (issued June 17, 2020) does not comply with BR section 7.1.6.1, including findings about other CA certificates.
- Mozilla representative — Mozilla stated an interpretation that BR section 7.1.6.1 focuses on end-entity certificate policy OIDs and that it allows use of both OV and DV policy identifiers in the same subordinate CA, and suggested clarifying the language with the CA/Browser Forum.
- GlobalSign nv-sa — GlobalSign said a CABForum draft ballot (“Cleanups and Clarifications”) includes updates to clarify section 7.1.6.1, endorsed the draft, and referenced a GitHub commit.
- Mozilla representative — Mozilla said it intended to close the matter on or about 14-Sept-2020 unless other issues were raised.