← GlobalSign nv-sa cases
Bugzilla #1668005 Self Incident Disclosure

GlobalSign: Failure to provide a preliminary report within 24 hours

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that it exceeded the Baseline Requirements #4.9.5 timeline for acknowledging a certificate problem report. The CA stated that it received two misissuance-related cases via its report-abuse email address on 25/09/2020 at 20:55 BST and 21:37 BST, but acknowledged them only on 27/09/2020 at 20:54 BST, which exceeded the required 24 hours. GlobalSign said it would provide a full incident report by Friday October 2. In the thread, GlobalSign described a timeline in which Compliance began investigation on 27/09/2020 and, together with Security and Support, concluded that the Support process for misissuance cases lacked critical steps (including immediate escalation to Compliance) and that the SOC process lacked evidence requirements for the response sent to the reporter. GlobalSign stated that it updated Support, SOC, and Compliance processes, including escalating misissuance cases to Compliance immediately and requesting evidence of the (preliminary) report every 4 hours until provided. The bug was later marked RESOLVED with resolution FIXED, and Mozilla indicated it could be closed after 20-November-2020.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.86 5 comments
Chronology
  1. GlobalSign received two misissuance-related cases via its report-abuse email address.
  2. GlobalSign acknowledged the received cases after the required 24-hour window.
  3. GlobalSign provided the requested incident-response timeline and process updates.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign stated it acknowledged two certificate problem reports after the 24-hour requirement and said it would provide a full incident report by Oct 2.
  2. GlobalSign nv-sa — GlobalSign provided details on when it became aware of the problem, the timeline of actions, and process updates to address the delayed preliminary reporting.
  3. GlobalSign nv-sa — GlobalSign asked whether more information was required or the ticket could be closed.
  4. Mozilla representative — Mozilla said the issue could be closed and scheduled closure for 20-November-2020.
Participants
GlobalSign nv-sa Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1694460 RESOLVED Self Reported Incident Opened 2021-02-23 · Closed 2022-11-14 · 62% similar
GlobalSign: Issuing CA certificate with wrong notBefore date
#1654544 RESOLVED Self Incident Disclosure Opened 2020-07-22 · Closed 2023-02-22 · 62% similar
GlobalSign: Use of Domain Validation Random Value for more than 30 days
#1668007 RESOLVED Ca Certificate Compliance Opened 2020-09-29 · Closed 2023-02-22 · 61% similar
GlobalSign: Invalid stateOrProvinceName value
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 61% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 61% similar
GlobalSign: Invalid countryName
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 61% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1622505 RESOLVED Ca Security Vulnerability Opened 2020-03-14 · Closed 2023-02-22 · 61% similar
GlobalSign: OCSP Status HTTP 530
#1649937 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 61% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action