GlobalSign: S/MIME sponsor-validated certificates mis-issued with Subject:commonName equal to Subject:organizationName
GlobalSign reported a compliance issue discovered during its quarterly internal audit on 2023-11-27. The audit identified three S/MIME legacy-profile sponsor-validated certificates whose Subject:commonName value was equal to Subject:organizationName, which GlobalSign stated did not meet S/MIME BRs section 7.1.4.2.2 permitted values for Subject:commonName. GlobalSign investigated and determined the certificates were issued by Enterprise RA accounts, where identity authentication for the individual is delegated to the Enterprise RA, and the Enterprise RAs erroneously provided only organization information in Subject:commonName. GlobalSign initiated a revocation and replacement process and later confirmed that all affected certificates were revoked by 2023-12-01 21:54 UTC. GlobalSign also set up monitoring and alerting, reached out to affected customers about permitted Subject:commonName values, and planned a custom lint to block sponsor-validated certificates with Subject:commonName equal to Subject:organizationName. During the production zlint deployment, GlobalSign encountered two additional certificate issuances that were revoked within 5 days, and the remedial activities were concluded with the expectation that the issue could be closed.
- GlobalSign discovered during a quarterly internal audit that some S/MIME sponsor-validated certificates had Subject:commonName equal to Subject:organizationName.
- GlobalSign initiated revocation and replacement for the affected certificates and began reviewing historically issued certificates.
- GlobalSign revoked the initially identified affected certificates.
- GlobalSign completed production zlint deployment and revoked two additional certificates issued during monitoring within 5 days.
- GlobalSign nv-sa — Reported that an internal audit found three S/MIME sponsor-validated certificates with Subject:commonName equal to Subject:OrganizationName and said an incident report would follow.
- GlobalSign nv-sa — Posted a detailed incident report describing the S/MIME BRs requirement, the impact (11 mis-issued certificates), the investigation, and planned mitigations including revocation, monitoring, customer outreach, and a blocking lint.
- GlobalSign nv-sa — Confirmed that all affected certificates were revoked by 2023-12-01 21:54 UTC.
- GlobalSign nv-sa — Stated they were on track to deploy the new lint to staging by 2023-12-15.
- GlobalSign nv-sa — Announced a schedule adjustment to deploy the lint release to staging by 2024-01-08 while keeping the production release latest by 2024-01-29.
- GlobalSign nv-sa — Confirmed staging deployment was completed and production release was on schedule.
- GlobalSign nv-sa — Reported production zlint deployment completion, noted two additional issuances found during monitoring that were revoked within 5 days, and said remedial activities were concluded and the issue could be closed.
- Mozilla representative — Requested closing the bug on Wed. 31-Jan-2023.