← GlobalSign nv-sa cases
Bugzilla #1760311 Ca Certificate Compliance Certificate Misissuance

GlobalSign: OCSP responder certificates with more than 64 characters in the CommonName field

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that it issued OCSP responder certificates whose CommonName field exceeded the allowed length of 64 characters. The issue was first noticed during a gap assessment of certificate profiles against proposed upcoming baseline requirement changes on 30/11/2021, and GlobalSign updated OCSP responder certificate profiles to use the CA shortname instead of the longer CA CN, then created OCSP responders using the updated profile in late February 2022. On 17/03/2022, a certificate problem report brought two OCSP responder certificates with CNs longer than 64 characters to GlobalSign’s attention; the Compliance team investigated and confirmed the reported certificates required revocation on 18/03/2022. GlobalSign completed review of historically issued certificates, identified four additional affected certificates, and started revocation. All affected certificates were revoked on 18/03/2022. As remediation, GlobalSign added linting to OCSP responder certificate profiles on 23/03/2022 and reviewed the linting configuration for all OCSP responder profiles. The bug was resolved as FIXED and GlobalSign stated it believed the issue could be closed unless further questions were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:56 UTC Confidence: 0.86 9 comments
Chronology
  1. GlobalSign noticed OCSP responder certificates with CommonName longer than 64 characters during gap assessment of certificate profiles.
  2. GlobalSign updated OCSP responder certificate profiles to use the CA shortname and created OCSP responders using the new profile.
  3. GlobalSign received a certificate problem report identifying OCSP responder certificates with CommonName longer than 64 characters.
  4. GlobalSign confirmed affected OCSP responder certificates required revocation and revoked all affected certificates.
  5. GlobalSign added linting to OCSP responder certificate profiles and reviewed linting configuration.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign stated it had issued six OCSP responder certificates with more than 64 characters in the CommonName field and would post a full incident report by March 23, 2022.
  2. GlobalSign nv-sa — GlobalSign provided an incident report describing how the issue was noticed, how the profile change was made, how the certificate problem report was received, what investigation and revocation actions were taken, and what remediation steps were completed.
  3. GlobalSign nv-sa — GlobalSign said it had concluded the identified remedial activities and believed the issue could be closed unless there were further questions.
  4. Community commenter — Ryan Sleevi suggested using the “Needs Info” flag if feedback was desired and noted the assignee remains responsible for ensuring the incident report process is followed.
  5. Community commenter — Ryan Sleevi commented that a timeline for the gap analysis seems reasonable and asked about systemic risks for intermediates and roots.
  6. GlobalSign nv-sa — GlobalSign responded that root and intermediate certificates are reviewed and passed through a linter by the compliance team as part of key ceremony review, and confirmed coverage for OCSP and WebPKI subscriber profiles.
  7. GlobalSign nv-sa — GlobalSign reiterated that if there were no further questions, it believed the issue could be closed.
  8. Mozilla representative — Mozilla stated it would close the bug on Friday, 6-May-2022, unless additional items or questions remained.
Participants
GlobalSign nv-sa Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 100% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 100% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 100% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 100% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 98% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1870276 RESOLVED Certificate Misissuance Opened 2023-12-15 · Closed 2024-01-24 · 95% similar
GlobalSign: TLS OV Certificate containing unverified information
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 89% similar
GlobalSign Partner: No SAN
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 88% similar
QuoVadis: Incorrect keyUsage for ECC certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action