GlobalSign: Use of Domain Validation Random Value for more than 30 days
This case describes a compliance issue at GlobalSign involving domain validation random values (RVs) being reused for longer than the 30-day limit required by Mozilla Baseline Requirements effective June 1, 2020. GlobalSign stated that, starting July 1, some actively used random values were not updated within the 30-day period due to a failure of a script intended to reset CloudSSL 1.0 random values. As a result, 78 domains were validated using expired RVs over approximately one day, and those improperly validated domains were used for about the next two weeks to issue 101 certificates. GlobalSign said it stopped issuance of certificates with improperly validated domains as of 2020-07-15 08:00 GMT, reset the affected domains’ RVs to expired, and revoked all certificates issued relying on a random value longer than 30 days by 2020-07-17 13:30 GMT. In the thread, Mozilla asked for more detail on systemic failures and reporting; GlobalSign responded with additional explanation of how CloudSSL 1.0 RVs were reused and how the mitigation was to update RVs on a more frequent cadence (every 28 days) with verification. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated an intent to close it unless there were objections.
- GlobalSign reset random values that might be re-used within its legacy CloudSSL 1.0 product.
- Mozilla’s 30-day random value reuse requirement for domain validation took effect.
- The planned script execution to reset random values failed.
- GlobalSign identified that CloudSSL 1.0 random values were not reset as expected due to the script failure.
- GlobalSign ran the development team’s script to update CloudSSL 1.0 random values.
- GlobalSign reset domains validated with expired RVs to expired and stopped issuance of certificates with improperly validated domains.
- GlobalSign revoked all certificates issued relying on a random value longer than 30 days.
- GlobalSign nv-sa — GlobalSign reported that RVs were reused beyond 30 days due to a script failure, leading to 78 domains validated with expired RVs and 101 certificates issued, and described remediation including stopping issuance, resetting domains, and revoking certificates.
- Community commenter — Mozilla asked why the incident was not reported sooner and expressed concern about incomplete systemic analysis and staffing/incident-response failures.
- GlobalSign nv-sa — GlobalSign explained how CloudSSL 1.0 permitted RV reuse and stated that the mitigation was to update RVs every 28 days with verification, as the product is being EOLed.
- Community commenter — Mozilla requested more detail on the system design and how the newer system works regarding validation.
- GlobalSign nv-sa — GlobalSign described certificate orders and RV generation/reuse, and explained that in newer products domain validation is separated from issuance with RVs unique per domain and validated within 30 days.
- GlobalSign nv-sa — GlobalSign asked whether more information was required or whether the bug could be closed.
- Mozilla representative — Mozilla stated an intent to close the bug on 7-Sept-2020 unless there were objections.