← GlobalSign nv-sa cases
Bugzilla #1850091
Certificate Problem Report
GlobalSign: EV TLS certificate with only metadata in JOI State field
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign issued an EV TLS certificate that contained only metadata in the jurisdictionStateOrProvinceName field. The issue was reported on August 24, 2023, leading to an immediate investigation and revocation process. The affected certificate was revoked by August 29, 2023. GlobalSign has implemented monitoring and a pre-issuance linting tool to prevent similar issues in the future. The company is committed to ensuring compliance and has concluded the identified remedial activities.
Chronology
- Received report of the certificate issue
- Revocation of the affected certificate
- Deployment of pre-issuance custom lint
Participants
Christophe Bonjean
Eva Vansteenberge
External References
Similar Local Cases
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold”
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
GlobalSign: Certificate issued to FQDN with malformed CAA
GlobalSign: OCSP responder certificates with more than 64 characters in CN
GlobalSign: OV TLS certificate with incorrect countryName value for organization
GlobalSign: Invalid stateOrProvinceName value