← GlobalSign nv-sa cases
Bugzilla #1667944
Certificate Problem Report
GlobalSign: Empty SingleExtension in OCSP responses
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign identified an issue with their OCSP responses containing an empty SingleExtension, which was not compliant with relevant RFCs. The problem was discovered during a gap analysis related to changes in the Baseline Requirements. GlobalSign worked with PrimeKey to address the issue, leading to the release of a fixed version of their software. Migration to the updated systems was completed successfully, ensuring compliance moving forward.
Chronology
- Noticed issue with OCSP response and requested further testing.
- PrimeKey released version 7.4.3 which included a fix for the issue.
- Migration of all OCSP responders to new systems was completed.
Participants
Paul Brown
Ben Wilson
Ryan Sleevi
External References
Similar Local Cases
GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: Invalid stateOrProvinceName value
GlobalSign: Failure to revoke 2 noncompliant QWACs within 5 days
GoDaddy: OV Documentation Reuse
GlobalSign: Failure to provide a preliminary report within 24 hours
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName