GlobalSign: OCSP responder certificates with more than 64 characters in the CommonName field
GlobalSign reported that it issued OCSP responder certificates whose CommonName field exceeded the allowed length of 64 characters. The issue was first noticed during a gap assessment of certificate profiles against proposed upcoming baseline requirement changes on 30/11/2021, and GlobalSign updated OCSP responder certificate profiles to use the CA shortname instead of the longer CA CN, then created OCSP responders using the updated profile in late February 2022. On 17/03/2022, a certificate problem report brought two OCSP responder certificates with CNs longer than 64 characters to GlobalSign’s attention; the Compliance team investigated and confirmed the reported certificates required revocation on 18/03/2022. GlobalSign completed review of historically issued certificates, identified four additional affected certificates, and started revocation. All affected certificates were revoked on 18/03/2022. As remediation, GlobalSign added linting to OCSP responder certificate profiles on 23/03/2022 and reviewed the linting configuration for all OCSP responder profiles. The bug was resolved as FIXED and GlobalSign stated it believed the issue could be closed unless further questions were raised.
- GlobalSign noticed OCSP responder certificates with CommonName longer than 64 characters during gap assessment of certificate profiles.
- GlobalSign updated OCSP responder certificate profiles to use the CA shortname and created OCSP responders using the new profile.
- GlobalSign received a certificate problem report identifying OCSP responder certificates with CommonName longer than 64 characters.
- GlobalSign confirmed affected OCSP responder certificates required revocation and revoked all affected certificates.
- GlobalSign added linting to OCSP responder certificate profiles and reviewed linting configuration.
- GlobalSign nv-sa — GlobalSign stated it had issued six OCSP responder certificates with more than 64 characters in the CommonName field and would post a full incident report by March 23, 2022.
- GlobalSign nv-sa — GlobalSign provided an incident report describing how the issue was noticed, how the profile change was made, how the certificate problem report was received, what investigation and revocation actions were taken, and what remediation steps were completed.
- GlobalSign nv-sa — GlobalSign said it had concluded the identified remedial activities and believed the issue could be closed unless there were further questions.
- Community commenter — Ryan Sleevi suggested using the “Needs Info” flag if feedback was desired and noted the assignee remains responsible for ensuring the incident report process is followed.
- Community commenter — Ryan Sleevi commented that a timeline for the gap analysis seems reasonable and asked about systemic risks for intermediates and roots.
- GlobalSign nv-sa — GlobalSign responded that root and intermediate certificates are reviewed and passed through a linter by the compliance team as part of key ceremony review, and confirmed coverage for OCSP and WebPKI subscriber profiles.
- GlobalSign nv-sa — GlobalSign reiterated that if there were no further questions, it believed the issue could be closed.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 6-May-2022, unless additional items or questions remained.