← GlobalSign nv-sa cases
Bugzilla #1793441 Ca Certificate Compliance Certificate Misissuance

GlobalSign: CRL contains invalid signature algorithm

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug reports that a GlobalSign CRL contained a signature algorithm that did not match the CA key type. The reporter noted that the CA uses an elliptic curve key, but the CRL signature algorithm was `sha256WithRSAEncryption`, and attached a copy of the CRL. GlobalSign acknowledged the issue and said it would review the signature algorithm configuration of the affected CRL, investigate, and provide an incident report by October 7, 2022. In its incident report, GlobalSign stated it became aware following the Bugzilla ticket and that it confirmed there were currently no active non-expired certificates issued from the affected CRL and that no other active CRLs were affected. GlobalSign explained the mistake as logic that determined the CRL signing algorithm OID based on the certificate of the CA signing the CRL, and said an exceptional ECC/RSA hierarchy combination was not covered by testing. GlobalSign updated the CRL signing algorithm logic to select the signing algorithm OID based on the issuer key, added test cases for ECC and RSA hierarchies, and stated the updated code was expected to be deployed in production by October 14, 2022. GlobalSign later confirmed the updated CRL logic was deployed and that the CRL is generated with the appropriate signing algorithm, and Mozilla indicated it intended to close the case around October 19, 2022.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 5 comments
Chronology
  1. A Bugzilla ticket was filed reporting that a GlobalSign CRL had an invalid signature algorithm.
  2. GlobalSign deployed updated CRL signing logic and confirmed the CRL is generated with the appropriate signing algorithm.
Thread Activity
  1. Community commenter — Created the bug and attached a copy of the CRL, stating the CRL used `sha256WithRSAEncryption` despite the CA using an elliptic curve key.
  2. GlobalSign nv-sa — Acknowledged the issue and said GlobalSign would review the CRL signature algorithm configuration, investigate, and provide an incident report by October 7, 2022.
  3. GlobalSign nv-sa — Provided an incident report describing how the wrong signing algorithm OID was included and the remediation steps planned (logic update and added test cases).
  4. GlobalSign nv-sa — Confirmed the updated CRL logic was deployed and that the CRL is generated with the appropriate signing algorithm, stating remedial activities were concluded.
  5. Mozilla representative — Stated an intention to close the case on or about 19-Oct-2022.
Participants
Mm representative GlobalSign nv-sa Mozilla representative
Similar Local Cases
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 86% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 86% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 85% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 85% similar
e-commerce monitoring GmbH: SCT in precertificate
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 84% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1425478 RESOLVED Certificate Misissuance Opened 2017-12-15 · Closed 2024-05-09 · 80% similar
GlobalSign: Invalid Common Names in Globalsign Certificates
#1353833 RESOLVED Certificate Misissuance Validation Issue Opened 2017-04-05 · Closed 2023-02-22 · 79% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 78% similar
KIR S.A.: Invalid organizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action