← GlobalSign nv-sa cases
Bugzilla #1829195
Certificate Problem Report
GlobalSign: CRLs reported in CCADB unavailable
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign reported that six Certificate Revocation Lists (CRLs) were unavailable in the CCADB, with five related to expired Certificate Authorities (CAs). An incorrect CRL URL was identified and updated in the CCADB. The issue was first reported via email to Mozilla Dev Security on April 19, 2023, and GlobalSign confirmed the problem shortly thereafter. A daily monitoring system for CRL availability has been implemented to prevent future occurrences.
Chronology
- GlobalSign informed Mozilla Dev Security about CRL issues.
- GlobalSign updated CCADB for the affected CA.
- Daily monitoring for CRL availability successfully deployed.
Participants
Christophe Bonjean
B. Wilson
External References
Similar Local Cases
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
GlobalSign: Certificate issued to FQDN with malformed CAA
GlobalSign: OCSP responder certificates with more than 64 characters in CN
GlobalSign: EV TLS certificate with only metadata in JOI State field
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold”
GlobalSign: misalignment of CRL URL in CCADB with issued certificates
Globalsign: Delayed revocation
GlobalSign: Incorrect whois information for TLD