← GlobalSign nv-sa cases
Bugzilla #1654544 Self Incident Disclosure

GlobalSign: Use of Domain Validation Random Value for more than 30 days

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes a compliance issue at GlobalSign involving domain validation random values (RVs) being reused for longer than the 30-day limit required by Mozilla Baseline Requirements effective June 1, 2020. GlobalSign stated that, starting July 1, some actively used random values were not updated within the 30-day period due to a failure of a script intended to reset CloudSSL 1.0 random values. As a result, 78 domains were validated using expired RVs over approximately one day, and those improperly validated domains were used for about the next two weeks to issue 101 certificates. GlobalSign said it stopped issuance of certificates with improperly validated domains as of 2020-07-15 08:00 GMT, reset the affected domains’ RVs to expired, and revoked all certificates issued relying on a random value longer than 30 days by 2020-07-17 13:30 GMT. In the thread, Mozilla asked for more detail on systemic failures and reporting; GlobalSign responded with additional explanation of how CloudSSL 1.0 RVs were reused and how the mitigation was to update RVs on a more frequent cadence (every 28 days) with verification. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated an intent to close it unless there were objections.

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.86 8 comments
Chronology
  1. GlobalSign reset random values that might be re-used within its legacy CloudSSL 1.0 product.
  2. Mozilla’s 30-day random value reuse requirement for domain validation took effect.
  3. The planned script execution to reset random values failed.
  4. GlobalSign identified that CloudSSL 1.0 random values were not reset as expected due to the script failure.
  5. GlobalSign ran the development team’s script to update CloudSSL 1.0 random values.
  6. GlobalSign reset domains validated with expired RVs to expired and stopped issuance of certificates with improperly validated domains.
  7. GlobalSign revoked all certificates issued relying on a random value longer than 30 days.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign reported that RVs were reused beyond 30 days due to a script failure, leading to 78 domains validated with expired RVs and 101 certificates issued, and described remediation including stopping issuance, resetting domains, and revoking certificates.
  2. Community commenter — Mozilla asked why the incident was not reported sooner and expressed concern about incomplete systemic analysis and staffing/incident-response failures.
  3. GlobalSign nv-sa — GlobalSign explained how CloudSSL 1.0 permitted RV reuse and stated that the mitigation was to update RVs every 28 days with verification, as the product is being EOLed.
  4. Community commenter — Mozilla requested more detail on the system design and how the newer system works regarding validation.
  5. GlobalSign nv-sa — GlobalSign described certificate orders and RV generation/reuse, and explained that in newer products domain validation is separated from issuance with RVs unique per domain and validated within 30 days.
  6. GlobalSign nv-sa — GlobalSign asked whether more information was required or whether the bug could be closed.
  7. Mozilla representative — Mozilla stated an intent to close the bug on 7-Sept-2020 unless there were objections.
Participants
GlobalSign nv-sa Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 69% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1668007 RESOLVED Ca Certificate Compliance Opened 2020-09-29 · Closed 2023-02-22 · 68% similar
GlobalSign: Invalid stateOrProvinceName value
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 68% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 68% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1649937 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 68% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate
#1622505 RESOLVED Ca Security Vulnerability Opened 2020-03-14 · Closed 2023-02-22 · 66% similar
GlobalSign: OCSP Status HTTP 530
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 65% similar
GlobalSign: Invalid countryName
#1668005 RESOLVED Self Incident Disclosure Opened 2020-09-29 · Closed 2023-02-22 · 62% similar
GlobalSign: Failure to provide a preliminary report within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action