← GlobalSign nv-sa cases
Bugzilla #1845803 Certificate Problem Report

GlobalSign: Three (3) revoked precertificates with CRL reasonCode “certificateHold”

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chrome Root Program monitoring observed three revoked certificate entries on CRLs disclosed to the CCADB with CRL reasonCode “certificateHold,” which conflicts with Baseline Requirements Section 7.2.2 (“CRL and CRL entry extensions”), stating the CRLReason MUST NOT be certificateHold for certificates subject to the Requirements. The affected certificates were identified via crt.sh links, and GlobalSign acknowledged the issue and began an investigation. GlobalSign reported that the problem was caused by EJBCA’s Precertificate_Revocation_Service when no certificate is created, and it confirmed additional occurrences including one on an expired certificate. GlobalSign stated it unsuspended four affected precertificates and suspended the Precertificate_Revocation_Service pending impact analysis, then resumed it after the investigation. GlobalSign later stated that the revocation status was corrected so the revocation reason is reflected as “superseded” on both CRL and OCSP, and that CRL profile-based compliance monitoring was deployed and completed. Mozilla’s reviewer asked GlobalSign to ensure its inquiry would have tested scenarios that could generate the errors if the same faulty EJBCA version were present; GlobalSign agreed and described process updates to prevent recurrence. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 9 comments
Chronology
  1. Chrome Root Program monitoring observed three revoked CRL entries with reasonCode “certificateHold” and reported the issue to Mozilla/CCADB.
  2. GlobalSign confirmed the issue was caused by EJBCA Precertificate_Revocation_Service behavior when no certificate is created and took steps to suspend/resume the service.
  3. GlobalSign upgraded EJBCA production cluster nodes to version 7.11.
  4. GlobalSign completed deployment of CRL profile-based compliance monitoring.
Thread Activity
  1. Google representative — Created the bug after observing three revoked CRL entries with reasonCode “certificateHold” and cited Baseline Requirements Section 7.2.2.
  2. GlobalSign nv-sa — Acknowledged the issue, started an investigation, and said a full incident report would be provided by 2023-08-01.
  3. GlobalSign nv-sa — Provided an incident report including a timeline and stated the root cause was EJBCA Precertificate_Revocation_Service when no certificate is created.
  4. Thisisntrocket representative — Noted that OCSP currently reported “good” while CRL showed revoked entries, and questioned whether “un-suspending” removed CRL entries.
  5. GlobalSign nv-sa — Responded that revocation status is now presented correctly with reason “superseded” on both CRL and OCSP and noted CRLs may take up to 24 hours to appear.
  6. GlobalSign nv-sa — Reported that internal ticket handling was extended and EJBCA production cluster nodes were upgraded to 7.11 on 2023-08-08, with CRL profile-based compliance monitoring ongoing.
  7. GlobalSign nv-sa — Stated CRL profile-based compliance monitoring deployment was completed and the action plan for the incident concluded.
  8. Mozilla representative — Observed that GlobalSign’s initial inquiry only checked existing CRLs for certificateHold and suggested scenario-based testing should have been done.
  9. GlobalSign nv-sa — Agreed and described updates to internal ticket handling, change management, and release note analysis processes to prevent recurrence.
Participants
Google representative GlobalSign nv-sa Thisisntrocket representative Mozilla representative
Similar Local Cases
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 60% similar
GlobalSign: CRL contains invalid signature algorithm
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 50% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName
#1870276 RESOLVED Certificate Misissuance Opened 2023-12-15 · Closed 2024-01-24 · 49% similar
GlobalSign: TLS OV Certificate containing unverified information
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 48% similar
GlobalSign: Invalid countryName
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 46% similar
SHA-1 issuance by GlobalSign root
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 45% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1353833 RESOLVED Certificate Misissuance Validation Issue Opened 2017-04-05 · Closed 2023-02-22 · 44% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1425478 RESOLVED Certificate Misissuance Opened 2017-12-15 · Closed 2024-05-09 · 44% similar
GlobalSign: Invalid Common Names in Globalsign Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action