Globalsign: Delayed revocation
This case involves GlobalSign's delayed revocation of certificates following reports of compromised keys due to a Fortigate leak. The issue arose when the CA did not receive two Certificate Problem Reports (CPRs) because the email attachments were blocked by their anti-malware settings. After the reports were eventually received, GlobalSign revoked the affected certificates within 24 hours. An incident report was generated, detailing the root cause as the blocking of the .xz file type, which was recognized as malware. GlobalSign has since implemented a quarterly validation process for email deliverability of CPRs to prevent future occurrences.
- Hanno Boeck reported delayed revocation incident for GlobalSign.
- GlobalSign began investigation and reached out to the reporter.
- GlobalSign revoked the affected certificates.
- GlobalSign deployed a validation process for CPR deliverability.
- Hboeck representative — Reported a delayed revocation incident for GlobalSign.
- GlobalSign nv-sa — Investigation has started and we have reached out to the reporter.
- GlobalSign nv-sa — All affected certificates were revoked.
- GlobalSign nv-sa — Validation of deliverability process was deployed.