← GlobalSign nv-sa cases
Bugzilla #1690807
Incident
Self Reported Incident
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GlobalSign disclosed a compliance failure involving the issuance of a leaf certificate with an RSA-1024 key, which contravenes the Baseline Requirements established over seven years ago. The CA became aware of the issue through a Bugzilla report on February 4, 2021, and promptly revoked the certificate. An incident report was submitted detailing the timeline of events and actions taken, including enabling linting for their certificate issuance processes. Remedial actions have been completed, including the deployment of an additional linter to prevent future occurrences.
Chronology
- GlobalSign issued a leaf certificate with an RSA-1024 key.
- GlobalSign revoked the non-compliant certificate.
- GlobalSign submitted a detailed incident report.
- GlobalSign completed all remedial actions.
Thread Activity
- Sectigo — Reported the issuance of a leaf certificate with an RSA-1024 key.
- GlobalSign nv-sa — Confirmed the revocation of the certificate and promised an incident report.
- GlobalSign nv-sa — Submitted a detailed incident report outlining the timeline and actions taken.
- GlobalSign nv-sa — Announced the completion of all remedial actions.
Participants
Sectigo
GlobalSign nv-sa
Community commenter
Mozilla representative
External References
Similar Local Cases
GlobalSign: Issuing CA certificate with wrong notBefore date
GlobalSign: Invalid countryName
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
GlobalSign: Certificate issued with RSASSA-PSS public key
GlobalSign: Incorrect OCSP Delegated Responder Certificate
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName