GlobalSign: Three (3) revoked precertificates with CRL reasonCode “certificateHold”
Chrome Root Program monitoring observed three revoked certificate entries on CRLs disclosed to the CCADB with CRL reasonCode “certificateHold,” which conflicts with Baseline Requirements Section 7.2.2 (“CRL and CRL entry extensions”), stating the CRLReason MUST NOT be certificateHold for certificates subject to the Requirements. The affected certificates were identified via crt.sh links, and GlobalSign acknowledged the issue and began an investigation. GlobalSign reported that the problem was caused by EJBCA’s Precertificate_Revocation_Service when no certificate is created, and it confirmed additional occurrences including one on an expired certificate. GlobalSign stated it unsuspended four affected precertificates and suspended the Precertificate_Revocation_Service pending impact analysis, then resumed it after the investigation. GlobalSign later stated that the revocation status was corrected so the revocation reason is reflected as “superseded” on both CRL and OCSP, and that CRL profile-based compliance monitoring was deployed and completed. Mozilla’s reviewer asked GlobalSign to ensure its inquiry would have tested scenarios that could generate the errors if the same faulty EJBCA version were present; GlobalSign agreed and described process updates to prevent recurrence. The bug is marked RESOLVED with resolution FIXED.
- Chrome Root Program monitoring observed three revoked CRL entries with reasonCode “certificateHold” and reported the issue to Mozilla/CCADB.
- GlobalSign confirmed the issue was caused by EJBCA Precertificate_Revocation_Service behavior when no certificate is created and took steps to suspend/resume the service.
- GlobalSign upgraded EJBCA production cluster nodes to version 7.11.
- GlobalSign completed deployment of CRL profile-based compliance monitoring.
- Google representative — Created the bug after observing three revoked CRL entries with reasonCode “certificateHold” and cited Baseline Requirements Section 7.2.2.
- GlobalSign nv-sa — Acknowledged the issue, started an investigation, and said a full incident report would be provided by 2023-08-01.
- GlobalSign nv-sa — Provided an incident report including a timeline and stated the root cause was EJBCA Precertificate_Revocation_Service when no certificate is created.
- Thisisntrocket representative — Noted that OCSP currently reported “good” while CRL showed revoked entries, and questioned whether “un-suspending” removed CRL entries.
- GlobalSign nv-sa — Responded that revocation status is now presented correctly with reason “superseded” on both CRL and OCSP and noted CRLs may take up to 24 hours to appear.
- GlobalSign nv-sa — Reported that internal ticket handling was extended and EJBCA production cluster nodes were upgraded to 7.11 on 2023-08-08, with CRL profile-based compliance monitoring ongoing.
- GlobalSign nv-sa — Stated CRL profile-based compliance monitoring deployment was completed and the action plan for the incident concluded.
- Mozilla representative — Observed that GlobalSign’s initial inquiry only checked existing CRLs for certificateHold and suggested scenario-based testing should have been done.
- GlobalSign nv-sa — Agreed and described updates to internal ticket handling, change management, and release note analysis processes to prevent recurrence.