← GlobalSign nv-sa cases
Bugzilla #1664328 Policy Compliance

GlobalSign: SHA-256 hash algorithm used with ECC P-384 key

RESOLVED FIXED GlobalSign nv-sa
AI Summary

GlobalSign faced an issue where certificates issued by their ECC CloudSSL CA with a P-384 key were incorrectly signed using ECDSA with SHA-256 instead of the required SHA-384. This discrepancy was identified during an investigation triggered by an unrelated incident. GlobalSign acknowledged the problem and ceased issuance of affected certificates, implementing measures to ensure compliance with cryptographic standards. The incident was resolved with a commitment to enhance their compliance processes and historical data analysis capabilities.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Confidence: 0.95
Chronology
  1. Incident detected regarding incorrect signature algorithm.
  2. GlobalSign ceased issuance of certificates with incorrect algorithm.
  3. Bug closed after compliance improvements were implemented.
Participants
Rob Stradling Arvid Vermote Paul Brown Ryan Sleevi Ben Wilson
Similar Local Cases
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 57% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1738778 RESOLVED Policy Compliance Opened 2021-11-01 · Closed 2023-02-22 · 56% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 56% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1649679 RESOLVED Policy Compliance Opened 2020-07-01 · Closed 2023-02-22 · 56% similar
Firmaprofesional: 2020 Audit Report Finding 2 out of 4
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 55% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1672029 RESOLVED Policy Compliance Opened 2020-10-19 · Closed 2023-02-22 · 54% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1525082 RESOLVED Policy Compliance Opened 2019-02-04 · Closed 2022-11-14 · 54% similar
Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate
#1713976 RESOLVED Policy Compliance Opened 2021-06-02 · Closed 2023-02-22 · 54% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action