← GlobalSign nv-sa cases
Bugzilla #1658932
Certificate Problem Report
GlobalSign: Incorrect Jurisdiction of Incorporation information for Japan
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign identified that three EV SSL certificates incorrectly included Jurisdiction of Incorporation information at the state and locality level for Japan, which should be at the country level. The issue was discovered on August 13, 2020, leading to the revocation of the certificates by August 18, 2020. An investigation was initiated to analyze other jurisdictions and ensure compliance with the Baseline Requirements. Subsequent reviews revealed additional certificates with similar issues, prompting further action and updates to their processes.
Chronology
- Initial discovery of incorrect jurisdiction information.
- Revocation of the three identified certificates.
- Detailed report on the incident provided.
- Additional 37 certificates identified with incorrect jurisdiction information.
- Publication of list of Incorporating and Registration Agencies.
Participants
Eva Van Steenberge
External References
Similar Local Cases
GlobalSign: Invalid countryName
GlobalSign: SSL Certificates with US country code and invalid State/Prov
GlobalSign: OV TLS certificate with incorrect countryName value for organization
GlobalSign: EV TLS certificate with only metadata in JOI State field
GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits