← GlobalSign nv-sa cases
Bugzilla #1934790
Certificate Problem Report
GlobalSign: OV TLS certificate with incorrect countryName value for organization
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign identified an issue with an OV TLS certificate that had an incorrect countryName value, resulting from customer changes during the renewal process. A Certificate Problem Report was received on December 2, 2024, leading to the revocation of the affected certificate on December 6, 2024. Further investigation revealed that 12 certificates had incorrect C, ST, or L combinations due to similar issues. Remedial actions included improving the vetting workflow to require explicit approval for changes and implementing an automated cross-checking feature for address information.
Chronology
- Certificate Problem Report received
- Affected certificate revoked
- Remedial actions completed
Participants
Christophe Bonjean
Pedro Fuentes
Ben Wilson
External References
Similar Local Cases
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
GlobalSign: OCSP responder certificates with more than 64 characters in CN
GlobalSign: EV TLS certificate with only metadata in JOI State field
GlobalSign: Invalid stateOrProvinceName value
GlobalSign: Certificate issued to FQDN with malformed CAA
Globalsign: Delayed revocation
GlobalSign: Empty SingleExtension in OCSP responses
GlobalSign: CRLs reported in CCADB unavailable