← GlobalSign nv-sa cases
Bugzilla #1650018 Certificate Misissuance

GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported an incident involving a cross certificate it created under a contract with Google, intended to allow Google to issue BR-compliant OV and DV leaf certificates and certain other certificate types. GlobalSign said it discovered issues while populating the Certificate Policies extension for this cross certificate in a BR-compliant manner, and it noted that the cross certificate was issued on June 17, 2020 and does not comply with CABF Baseline Requirements section 7.1.6.1. GlobalSign also stated that, upon investigation of issued subordinate CAs, it found four other CA certificates that include policy identifier 2.23.140.1.2.1 and organizationName in the Subject. In the thread, Mozilla’s representative discussed an interpretation of BR section 7.1.6.1 that would allow use of both policy identifiers (OV and DV) in the same subordinate CA, and suggested clarifying the provision with the CA/Browser Forum. GlobalSign stated it endorsed a CABForum draft ballot (“Cleanups and Clarifications”) intended to clarify section 7.1.6.1 and referenced a GitHub commit for the draft updates. The bug was resolved as FIXED, and Mozilla indicated an intention to close the matter on or about 14-Sept-2020 unless other issues were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.72 5 comments
Chronology
  1. GlobalSign issued the cross certificate from GlobalSign Root R1 to the Google GTS Root R1.
  2. GlobalSign opened a CA Program bug reporting the cross certificate’s non-compliance with CABF Baseline Requirements section 7.1.6.1.
  3. Mozilla discussed an interpretation of BR section 7.1.6.1 and the need for clarification.
  4. GlobalSign endorsed a CABForum draft ballot to clarify BR section 7.1.6.1.
  5. Mozilla indicated it intended to close the matter around 14-Sept-2020 unless new issues were raised.
  6. The bug was marked RESOLVED (FIXED).
Thread Activity
  1. GlobalSign nv-sa — GlobalSign described the Google cross-certificate arrangement, said it discovered issues populating Certificate Policies in a BR-compliant manner, and reported that the cross certificate (issued June 17, 2020) does not comply with BR section 7.1.6.1, including findings about other CA certificates.
  2. Mozilla representative — Mozilla stated an interpretation that BR section 7.1.6.1 focuses on end-entity certificate policy OIDs and that it allows use of both OV and DV policy identifiers in the same subordinate CA, and suggested clarifying the language with the CA/Browser Forum.
  3. GlobalSign nv-sa — GlobalSign said a CABForum draft ballot (“Cleanups and Clarifications”) includes updates to clarify section 7.1.6.1, endorsed the draft, and referenced a GitHub commit.
  4. Mozilla representative — Mozilla said it intended to close the matter on or about 14-Sept-2020 unless other issues were raised.
Participants
GlobalSign nv-sa Mozilla representative
Similar Local Cases
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 95% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 95% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 88% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1870276 RESOLVED Certificate Misissuance Opened 2023-12-15 · Closed 2024-01-24 · 88% similar
GlobalSign: TLS OV Certificate containing unverified information
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 87% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 86% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 86% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 81% similar
GlobalSign Partner: No SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action