← GlobalSign nv-sa cases
Bugzilla #1664328 Incident Self Reported Incident

GlobalSign: SHA-256 hash algorithm used with ECC P-384 key

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign identified a compliance issue where certificates issued by the 'GlobalSign ECC CloudSSL CA - SHA384 - G3' intermediate CA used ECDSA with SHA-256 instead of the required SHA-384 for P-384 keys. The issue was discovered during an investigation related to another incident. GlobalSign acknowledged the problem, ceased issuance of affected certificates, and revoked all non-expired certificates. They have since updated their compliance processes to ensure historical issuance data is reviewed for compliance with current requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.85 11 comments
Chronology
  1. GlobalSign acknowledges the compliance issue regarding SHA-256 usage.
  2. GlobalSign ceased issuance of certificates with the incorrect algorithm.
  3. GlobalSign updates compliance procedures to include historical data checks.
Thread Activity
  1. Sectigo — Reported that the signing key P-384 must use ECDSA with SHA-384.
  2. GlobalSign nv-sa — GlobalSign acknowledges the report and begins investigation.
  3. GlobalSign nv-sa — Provided a detailed incident report and timeline of actions taken.
  4. GlobalSign nv-sa — Confirmed that the bug can be closed as compliance processes are being improved.
Participants
Sectigo GlobalSign nv-sa Community commenter Mozilla representative
External References
Similar Local Cases
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 100% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1694460 RESOLVED Self Reported Incident Opened 2021-02-23 · Closed 2022-11-14 · 100% similar
GlobalSign: Issuing CA certificate with wrong notBefore date
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid countryName
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 100% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1630870 RESOLVED Self Reported Incident Opened 2020-04-17 · Closed 2023-02-22 · 100% similar
GlobalSign: Certificate issued with RSASSA-PSS public key
#1649937 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 100% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate
#1714968 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 98% similar
GlobalSign: Incorrect RegNumber-Org Type combination

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action