← GlobalSign nv-sa cases
Bugzilla #1866806 Self Reported Incident Certificate Misissuance

GlobalSign: S/MIME sponsor-validated certificates mis-issued with Subject:commonName equal to Subject:organizationName

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported a compliance issue discovered during its quarterly internal audit on 2023-11-27. The audit identified three S/MIME legacy-profile sponsor-validated certificates whose Subject:commonName value was equal to Subject:organizationName, which GlobalSign stated did not meet S/MIME BRs section 7.1.4.2.2 permitted values for Subject:commonName. GlobalSign investigated and determined the certificates were issued by Enterprise RA accounts, where identity authentication for the individual is delegated to the Enterprise RA, and the Enterprise RAs erroneously provided only organization information in Subject:commonName. GlobalSign initiated a revocation and replacement process and later confirmed that all affected certificates were revoked by 2023-12-01 21:54 UTC. GlobalSign also set up monitoring and alerting, reached out to affected customers about permitted Subject:commonName values, and planned a custom lint to block sponsor-validated certificates with Subject:commonName equal to Subject:organizationName. During the production zlint deployment, GlobalSign encountered two additional certificate issuances that were revoked within 5 days, and the remedial activities were concluded with the expectation that the issue could be closed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.90 9 comments
Chronology
  1. GlobalSign discovered during a quarterly internal audit that some S/MIME sponsor-validated certificates had Subject:commonName equal to Subject:organizationName.
  2. GlobalSign initiated revocation and replacement for the affected certificates and began reviewing historically issued certificates.
  3. GlobalSign revoked the initially identified affected certificates.
  4. GlobalSign completed production zlint deployment and revoked two additional certificates issued during monitoring within 5 days.
Thread Activity
  1. GlobalSign nv-sa — Reported that an internal audit found three S/MIME sponsor-validated certificates with Subject:commonName equal to Subject:OrganizationName and said an incident report would follow.
  2. GlobalSign nv-sa — Posted a detailed incident report describing the S/MIME BRs requirement, the impact (11 mis-issued certificates), the investigation, and planned mitigations including revocation, monitoring, customer outreach, and a blocking lint.
  3. GlobalSign nv-sa — Confirmed that all affected certificates were revoked by 2023-12-01 21:54 UTC.
  4. GlobalSign nv-sa — Stated they were on track to deploy the new lint to staging by 2023-12-15.
  5. GlobalSign nv-sa — Announced a schedule adjustment to deploy the lint release to staging by 2024-01-08 while keeping the production release latest by 2024-01-29.
  6. GlobalSign nv-sa — Confirmed staging deployment was completed and production release was on schedule.
  7. GlobalSign nv-sa — Reported production zlint deployment completion, noted two additional issuances found during monitoring that were revoked within 5 days, and said remedial activities were concluded and the issue could be closed.
  8. Mozilla representative — Requested closing the bug on Wed. 31-Jan-2023.
Participants
GlobalSign nv-sa Mozilla representative
External References
Similar Local Cases
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid countryName
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 100% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1850091 RESOLVED Self Reported Incident Opened 2023-08-25 · Closed 2023-10-12 · 100% similar
GlobalSign: EV TLS certificate with only metadata in JOI State field
#1934790 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-12-03 · Closed 2025-01-14 · 100% similar
GlobalSign: OV TLS certificate with incorrect countryName value for organization
#1599775 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-27 · Closed 2023-02-22 · 99% similar
GlobalSign: Wrong business category (Non Commercial Entity when should have been Private Organization)
#1714968 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 97% similar
GlobalSign: Incorrect RegNumber-Org Type combination
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 97% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1649937 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 96% similar
GlobalSign: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action