← GlobalSign nv-sa cases
Bugzilla #1870276 Certificate Misissuance

GlobalSign: TLS OV certificate issued with unverified subject information (internal test misissuance)

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that, on 2023-12-14 06:10 UTC, an internally requested test OV TLS certificate was issued containing unverified information in Subject fields (OrganizationName, stateOrProvinceName, localityName, and countryName). The certificate was revoked at discovery of the mis-issuance on 2023-12-14 06:38 UTC, and the case was escalated internally to the compliance team on 2023-12-14 06:56 UTC. In its incident report, GlobalSign attributed the event to miscommunication during an attempted production replication of a staging test, where vetting management approval was misunderstood and the validation specialist proceeded with issuance. GlobalSign stated that it issued only a single certificate and documented the incident timeline and root cause analysis. As remediation, GlobalSign reported updating its Acceptable Use Policy to restrict testing in production environments, establishing a formal escalation process with training, and completing an internal investigation of disciplinary actions. GlobalSign also stated it deployed a technical and automated control to block certificates with “test” values in the Subject DN (excluding CN) without further compliance approval. Mozilla indicated it would close the bug on 2024-01-24 unless there were reasons to keep it open, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 10 comments
Chronology
  1. GlobalSign issued an internally requested OV TLS test certificate containing unverified Subject information, then revoked it after discovery.
  2. GlobalSign published an incident report describing the timeline, root cause, and action items.
  3. GlobalSign reported completion of remaining action items and requested closure.
Thread Activity
  1. GlobalSign nv-sa — Reported that an internally requested certificate was issued with unverified Subject information, then revoked at discovery and escalated to compliance, with an incident report planned.
  2. GlobalSign nv-sa — Posted the incident report including impact, timeline, root cause analysis, and action items.
  3. Community commenter — Commented that disciplinary actions are not endorsed by root programs and do not prevent recurrence.
  4. GlobalSign nv-sa — Responded that disciplinary actions are part of ensuring validation specialists perform duties satisfactorily and described additional technical controls.
  5. GlobalSign nv-sa — Noted no scheduled deliverables that week and that other actions were on track.
  6. GlobalSign nv-sa — Noted no scheduled deliverables that week and that other actions were on track.
  7. Community commenter — Asked whether adding a second review for organization-validated TLS was evaluated.
  8. GlobalSign nv-sa — Said a second review option was evaluated but determined not to be effective/proportional, and described why other measures were chosen.
  9. GlobalSign nv-sa — Reported completion of remaining action items (Acceptable Use Policy update, formal escalation process and training, and disciplinary actions investigation) and requested closure.
  10. Mozilla representative — Indicated the bug would be closed on 2024-01-24 unless there were reasons to keep it open.
Participants
GlobalSign nv-sa Community commenter Mozilla representative
External References
Similar Local Cases
#1744518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 99% similar
GlobalSign: EV certificates with serialNumber Government Entity and businessCategory Private Organization
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 98% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 98% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1836443 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-06-02 · Closed 2024-06-30 · 96% similar
GlobalSign: Issuance of test certificate (pre-certificate) for EV SSL/QWAC with no EKU extension
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 95% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 90% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1650018 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 88% similar
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 84% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action