← GlobalSign nv-sa cases
Bugzilla #1664328
Incident
Self Reported Incident
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GlobalSign identified a compliance issue where certificates issued by the 'GlobalSign ECC CloudSSL CA - SHA384 - G3' intermediate CA used ECDSA with SHA-256 instead of the required SHA-384 for P-384 keys. The issue was discovered during an investigation related to another incident. GlobalSign acknowledged the problem, ceased issuance of affected certificates, and revoked all non-expired certificates. They have since updated their compliance processes to ensure historical issuance data is reviewed for compliance with current requirements.
Chronology
- GlobalSign acknowledges the compliance issue regarding SHA-256 usage.
- GlobalSign ceased issuance of certificates with the incorrect algorithm.
- GlobalSign updates compliance procedures to include historical data checks.
Thread Activity
- Sectigo — Reported that the signing key P-384 must use ECDSA with SHA-384.
- GlobalSign nv-sa — GlobalSign acknowledges the report and begins investigation.
- GlobalSign nv-sa — Provided a detailed incident report and timeline of actions taken.
- GlobalSign nv-sa — Confirmed that the bug can be closed as compliance processes are being improved.
Participants
Sectigo
GlobalSign nv-sa
Community commenter
Mozilla representative
External References
Similar Local Cases
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
GlobalSign: Issuing CA certificate with wrong notBefore date
GlobalSign: Invalid countryName
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign: Incorrect OCSP Delegated Responder Certificate
GlobalSign: Incorrect RegNumber-Org Type combination