GlobalSign: EV certificate with wildcard domain in common name and SAN
GlobalSign reported that it issued an EV TLS certificate containing a wildcard domain in the subject common name and SAN fields. The CA said it first became aware of the issue via a system notification received by its compliance team on 30/07/2022 at 15:00 UTC. GlobalSign investigated, confirmed the mis-issuance, initiated a replacement process, reviewed historically issued certificates and outstanding requests, and found no additional certificates or affected requests. It stated that the root cause was a code bug in its MSSL ordering procedure where the system failed to trim the Common Name before applying the EV validation rule, allowing a wildcard to bypass the check due to leading whitespace; the whitespace was trimmed only after that validation step. GlobalSign applied a code fix in production, updated a linter in staging and production, and revoked the certificate on 02/08/2022. In follow-up, Mozilla asked about whether other wildcard/trim scenarios were evaluated, and GlobalSign described additional issuance-path checks and said it would add a single EV-specific validation in a platform release. The thread indicates remedial activities were concluded after the latest platform release was deployed, and Mozilla stated it would close the bug unless new issues were raised.
- GlobalSign received a compliance system notification indicating an EV certificate warning and began investigating a suspected mis-issuance.
- GlobalSign revoked the mis-issued EV TLS certificate.
- GlobalSign deployed the latest platform release completing the identified remedial activities.
- GlobalSign nv-sa — GlobalSign stated it issued one EV TLS certificate with a wildcard domain in the subject common name and SAN and said it would post a full incident report by August 3, 2022.
- GlobalSign nv-sa — GlobalSign provided a detailed incident narrative including how it became aware, its investigation timeline, the stated root cause, and remediation steps (including revocation and code/linter updates), and referenced https://crt.sh/?id=7231582044.
- Mozilla representative — Mozilla asked whether GlobalSign evaluated other cases where a wildcard might survive trimming and whether pre-issuance should prevent wildcards anywhere in CN or SAN for EV certificates.
- GlobalSign nv-sa — GlobalSign responded that CN/SAN are processed by two layers of checks and said it would add a single EV-specific validation in the next platform release expected by August 29th.
- GlobalSign nv-sa — GlobalSign stated the latest platform release was deployed and that remedial activities were concluded unless further questions were raised.
- Mozilla representative — Mozilla said it would close the bug on or about Friday 2-Sept-2022 unless new issues were raised.