← GlobalSign nv-sa cases
Bugzilla #1919304 Self Reported Incident

GlobalSign: Inaccurate HTTP caching headers for a subset of CRLs (Atlas platform)

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported that it received an external report indicating its CRL distribution points returned inaccurate HTTP caching headers for a subset of CRLs. In its incident report, GlobalSign stated that for CRLs published through its Atlas platform, the HTTP caching headers (Expires, Last-Modified, and ETag) were inaccurate between 2024-08-22 13:38 and 2024-09-13 15:10. GlobalSign said fresh CRLs were generated, published, and served, but a fault in the update process prevented the corresponding HTTP caching header values from being properly updated, resulting in incorrect (expired) caching headers for CRLs for 185 CAs. GlobalSign identified the root cause as stale configuration files due to a bug in the update process, where after an operating system upgrade the server reload command did not execute as expected and the new header settings were not loaded into memory. GlobalSign updated the configuration of both CRL servers with correct HTTP headers and updated scripts for publishing CRLs and reloading the configuration. It also extended monitoring to cover HTTP headers and completed updates to the QA process to ensure coverage of HTTP header responses and configuration reload behavior; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.86 5 comments
Chronology
  1. GlobalSign began publishing CRLs with incorrect (expired) HTTP caching header values on its Atlas platform.
  2. GlobalSign received a report about the CRL caching header issue and identified the root cause.
  3. GlobalSign updated CRL server configuration to correct HTTP caching headers and resolved the issue.
  4. GlobalSign extended monitoring to include correctness of HTTP headers.
  5. GlobalSign completed QA process updates for HTTP header responses and configuration reload behavior.
Thread Activity
  1. GlobalSign nv-sa — GlobalSign said it received a report that its CRL distribution points returned inaccurate caching headers for a subset of CRLs and would provide an incident report no later than 2024-09-24.
  2. GlobalSign nv-sa — GlobalSign posted an incident report describing the affected Atlas CRLs, impact, timeline, root cause, and action items including script updates, monitoring changes, and QA improvements.
  3. GlobalSign nv-sa — GlobalSign stated there were no scheduled deliverables that week and that it was on track to deliver remaining actions.
  4. GlobalSign nv-sa — GlobalSign reported completion of QA process updates for HTTP header responses and configuration reload behavior and said remedial activities were concluded.
  5. Mozilla representative — Mozilla indicated it would close the bug on 2024-10-18 unless there were still issues to discuss.
Participants
GlobalSign nv-sa Mozilla representative
External References
Similar Local Cases
#1917896 RESOLVED Self Reported Incident Opened 2024-09-10 · Closed 2025-03-18 · 95% similar
GlobalSign: Incorrect whois information for TLD
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 95% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 93% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName
#1934790 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-12-03 · Closed 2025-01-14 · 93% similar
GlobalSign: OV TLS certificate with incorrect countryName value for organization
#2034360 RESOLVED Ccadb Metadata Update Self Reported Incident Opened 2026-04-23 · Closed 2026-06-01 · 89% similar
GlobalSign: CRL Distribution Point URLs incomplete for Cross-Certified Root CAs in CCADB records
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 87% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1630870 RESOLVED Self Reported Incident Opened 2020-04-17 · Closed 2023-02-22 · 87% similar
GlobalSign: Certificate issued with RSASSA-PSS public key
#1694460 RESOLVED Self Reported Incident Opened 2021-02-23 · Closed 2022-11-14 · 86% similar
GlobalSign: Issuing CA certificate with wrong notBefore date

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action