GlobalSign: Issuance of EV SSL/QWAC test pre-certificate without EKU extension
GlobalSign reported that, during setup of a new service, it issued a test EV SSL/QWAC pre-certificate without an EKU extension. The issue was first detected when GlobalSign’s post linter notified its compliance team on 01/06/2023 at 10:03 UTC that a mis-issuance had occurred. GlobalSign began investigating at 10:05 UTC and confirmed at 10:06 UTC that the pre-certificate was mis-issued. It requested revocation at 10:11 UTC and revoked the pre-certificate at 11:27 UTC, and it stated that issuance was immediately stopped for the affected CA and that certificate issuance to certificate consumers had not been started for the affected public CA. GlobalSign explained that human error led to the test certificate request being sent to the public CA instead of the private demo CA, and that zlint was configured only at the profile level (not yet enabled at the CA level), so the certificate was not blocked during pre-issuance. The bug was resolved as FIXED.
- GlobalSign issued a test EV SSL/QWAC pre-certificate from the public CA without an EKU extension during setup of a new service.
- GlobalSign’s post linter reported the mis-issuance and GlobalSign revoked the affected pre-certificate the same day.
- GlobalSign nv-sa — GlobalSign described how it became aware of the mis-issuance via its post linter, provided a timeline, and explained the cause and remediation steps, including revocation of the pre-certificate.
- Mozilla representative — Mozilla asked whether there were any questions or comments and indicated it would close the bug on Friday, 15-Sept-2023 if none.