← GlobalSign nv-sa cases
Bugzilla #1668007
Certificate Problem Report
GlobalSign: Invalid stateOrProvinceName value
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign identified an issue where several certificates were issued with an incorrect 'stateOrProvinceName' value that included the country name. This misinterpretation of the guidelines led to the issuance of certificates that did not comply with the requirements. GlobalSign has since revoked the affected certificates and implemented measures to prevent future occurrences. A full incident report was provided detailing the timeline of events and corrective actions taken.
Chronology
- First certificate problem report received regarding ST fields.
- Compliance team confirms awareness of the issue and begins revocation process.
- GlobalSign submits initial incident report.
- Scan for certificates with incorrect values completed.
- Review of internal verification procedures completed.
Participants
Arvid Vermote
Eva Vansteenberge
George Fozzie
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Failure to revoke noncompliant ICA within 7 days
GlobalSign: Incorrect OCSP Delegated Responder Certificate
GlobalSign: Failure to revoke noncompliant certificates within 5 days
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
GlobalSign: Invalid countryName
GlobalSign: ICAs in CCADB, without EKU extension are listed in WTCA report but not in WTBR report
GlobalSign: Certificate issued with RSASSA-PSS public key