← GlobalSign nv-sa cases
Bugzilla #1917896 Self Reported Incident

GlobalSign: Incorrect whois information for TLD

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign identified incorrect WHOIS information for the .mobi TLD during automated validation processes, which could have led to potential mis-issuance. Although no mis-issuance was detected, GlobalSign raised this ticket for transparency. They updated their WHOIS references to the correct IANA server and audited their WHOIS configuration for other TLDs. Following the incident, they disabled automated WHOIS processes temporarily and implemented a change management process to monitor WHOIS server records. An incident report detailing their findings and actions is scheduled for release.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.85 19 comments
Chronology
  1. GlobalSign updated WHOIS references for .mobi to the IANA referenced server.
  2. GlobalSign completed audit of WHOIS configuration and identified discrepancies.
  3. GlobalSign planned to release a full incident report.
  4. GlobalSign deployed a new platform release to disable specific domain validation methods.
  5. GlobalSign completed actions related to the incident and prepared reporting queries.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign has been informed of incorrect whois information for a TLD and is investigating.
  2. GlobalSign nv-sa — GlobalSign updated WHOIS references for .mobi to the correct server.
  3. GlobalSign nv-sa — GlobalSign is on track to release the full incident report.
  4. GlobalSign nv-sa — GlobalSign successfully deployed a new platform release.
  5. GlobalSign nv-sa — GlobalSign completed the action of reviewing and preparing reporting queries.
Participants
GlobalSign nv-sa Community commenter Hezmatt representative Mozilla representative
External References
Similar Local Cases
#1707073 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-22 · Closed 2023-02-22 · 97% similar
GlobalSign: Invalid countryName
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 96% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1934790 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-12-03 · Closed 2025-01-14 · 96% similar
GlobalSign: OV TLS certificate with incorrect countryName value for organization
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 96% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1919304 RESOLVED Self Reported Incident Opened 2024-09-17 · Closed 2024-10-23 · 95% similar
GlobalSign: Caching headers inaccurate for subset of CRLs
#1694460 RESOLVED Self Reported Incident Opened 2021-02-23 · Closed 2022-11-14 · 94% similar
GlobalSign: Issuing CA certificate with wrong notBefore date
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 94% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 94% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action