← GlobalSign nv-sa cases
Bugzilla #1917896
Self Reported Incident
GlobalSign: Incorrect whois information for TLD
RESOLVED
FIXED
GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
GlobalSign identified incorrect WHOIS information for the .mobi TLD during automated validation processes, which could have led to potential mis-issuance. Although no mis-issuance was detected, GlobalSign raised this ticket for transparency. They updated their WHOIS references to the correct IANA server and audited their WHOIS configuration for other TLDs. Following the incident, they disabled automated WHOIS processes temporarily and implemented a change management process to monitor WHOIS server records. An incident report detailing their findings and actions is scheduled for release.
Chronology
- GlobalSign updated WHOIS references for .mobi to the IANA referenced server.
- GlobalSign completed audit of WHOIS configuration and identified discrepancies.
- GlobalSign planned to release a full incident report.
- GlobalSign deployed a new platform release to disable specific domain validation methods.
- GlobalSign completed actions related to the incident and prepared reporting queries.
Thread Activity
- GlobalSign nv-sa — GlobalSign has been informed of incorrect whois information for a TLD and is investigating.
- GlobalSign nv-sa — GlobalSign updated WHOIS references for .mobi to the correct server.
- GlobalSign nv-sa — GlobalSign is on track to release the full incident report.
- GlobalSign nv-sa — GlobalSign successfully deployed a new platform release.
- GlobalSign nv-sa — GlobalSign completed the action of reviewing and preparing reporting queries.
Participants
GlobalSign nv-sa
Community commenter
Hezmatt representative
Mozilla representative
External References
Similar Local Cases
GlobalSign: Invalid countryName
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
GlobalSign: OV TLS certificate with incorrect countryName value for organization
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
GlobalSign: Caching headers inaccurate for subset of CRLs
GlobalSign: Issuing CA certificate with wrong notBefore date
GlobalSign: Invalid stateOrProvinceName and locality pair
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName