← GlobalSign nv-sa cases
Bugzilla #1836443 Ca Certificate Compliance Certificate Misissuance

GlobalSign: Issuance of EV SSL/QWAC test pre-certificate without EKU extension

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that, during setup of a new service, it issued a test EV SSL/QWAC pre-certificate without an EKU extension. The issue was first detected when GlobalSign’s post linter notified its compliance team on 01/06/2023 at 10:03 UTC that a mis-issuance had occurred. GlobalSign began investigating at 10:05 UTC and confirmed at 10:06 UTC that the pre-certificate was mis-issued. It requested revocation at 10:11 UTC and revoked the pre-certificate at 11:27 UTC, and it stated that issuance was immediately stopped for the affected CA and that certificate issuance to certificate consumers had not been started for the affected public CA. GlobalSign explained that human error led to the test certificate request being sent to the public CA instead of the private demo CA, and that zlint was configured only at the profile level (not yet enabled at the CA level), so the certificate was not blocked during pre-issuance. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 3 comments
Chronology
  1. GlobalSign issued a test EV SSL/QWAC pre-certificate from the public CA without an EKU extension during setup of a new service.
  2. GlobalSign’s post linter reported the mis-issuance and GlobalSign revoked the affected pre-certificate the same day.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign described how it became aware of the mis-issuance via its post linter, provided a timeline, and explained the cause and remediation steps, including revocation of the pre-certificate.
  2. Mozilla representative — Mozilla asked whether there were any questions or comments and indicated it would close the bug on Friday, 15-Sept-2023 if none.
Participants
GlobalSign nv-sa Mozilla representative
External References
Similar Local Cases
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 100% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 100% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 100% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 99% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1870276 RESOLVED Certificate Misissuance Opened 2023-12-15 · Closed 2024-01-24 · 96% similar
GlobalSign: TLS OV Certificate containing unverified information
#1048045 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 89% similar
GlobalSign Partner: No SAN
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 88% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1650018 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 86% similar
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action