GlobalSign: TLS OV certificate issued with unverified subject information (internal test misissuance)
GlobalSign reported that, on 2023-12-14 06:10 UTC, an internally requested test OV TLS certificate was issued containing unverified information in Subject fields (OrganizationName, stateOrProvinceName, localityName, and countryName). The certificate was revoked at discovery of the mis-issuance on 2023-12-14 06:38 UTC, and the case was escalated internally to the compliance team on 2023-12-14 06:56 UTC. In its incident report, GlobalSign attributed the event to miscommunication during an attempted production replication of a staging test, where vetting management approval was misunderstood and the validation specialist proceeded with issuance. GlobalSign stated that it issued only a single certificate and documented the incident timeline and root cause analysis. As remediation, GlobalSign reported updating its Acceptable Use Policy to restrict testing in production environments, establishing a formal escalation process with training, and completing an internal investigation of disciplinary actions. GlobalSign also stated it deployed a technical and automated control to block certificates with “test” values in the Subject DN (excluding CN) without further compliance approval. Mozilla indicated it would close the bug on 2024-01-24 unless there were reasons to keep it open, and the bug is marked RESOLVED with resolution FIXED.
- GlobalSign issued an internally requested OV TLS test certificate containing unverified Subject information, then revoked it after discovery.
- GlobalSign published an incident report describing the timeline, root cause, and action items.
- GlobalSign reported completion of remaining action items and requested closure.
- GlobalSign nv-sa — Reported that an internally requested certificate was issued with unverified Subject information, then revoked at discovery and escalated to compliance, with an incident report planned.
- GlobalSign nv-sa — Posted the incident report including impact, timeline, root cause analysis, and action items.
- Community commenter — Commented that disciplinary actions are not endorsed by root programs and do not prevent recurrence.
- GlobalSign nv-sa — Responded that disciplinary actions are part of ensuring validation specialists perform duties satisfactorily and described additional technical controls.
- GlobalSign nv-sa — Noted no scheduled deliverables that week and that other actions were on track.
- GlobalSign nv-sa — Noted no scheduled deliverables that week and that other actions were on track.
- Community commenter — Asked whether adding a second review for organization-validated TLS was evaluated.
- GlobalSign nv-sa — Said a second review option was evaluated but determined not to be effective/proportional, and described why other measures were chosen.
- GlobalSign nv-sa — Reported completion of remaining action items (Acceptable Use Policy update, formal escalation process and training, and disciplinary actions investigation) and requested closure.
- Mozilla representative — Indicated the bug would be closed on 2024-01-24 unless there were reasons to keep it open.