← GlobalSign nv-sa cases
Bugzilla #1944815 Self Reported Incident Validation Issue

GlobalSign: Organization-validated S/MIME certificate issued with invalid Subject:organizationIdentifier (NTR scheme structure)

RESOLVED FIXED GlobalSign nv-sa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

GlobalSign reported a compliance incident after being notified by its post-linter of an organization-validated S/MIME certificate with an invalid Subject:organizationIdentifier structure. The Baseline Requirements for S/MIME require that for the NTR Registration Scheme, where the Legal Entity is registered within a European country, the NTR Registration Scheme must be assigned at the country level; the affected certificate included subdivision +BY, resulting in an invalid structure. GlobalSign stated that one organization-validated SMIME certificate was issued with an invalid organizationIdentifier value and that it completed a review of historically issued certificates and pending requests, finding no additional affected certificates. GlobalSign scheduled revocation for the affected certificate and later revoked it. In its incident report, GlobalSign attributed the root cause to a combination of human error, missing technical restrictions in the vetting workflow for the country-level assignment, and incomplete lint coverage in the pre-linter configuration during a transition period. GlobalSign reported remedial actions including deploying a technical restriction in the vetting flow, delivering refresher training to vetting agents, deploying pkilint as a pre-linter in production, and adding further technical restrictions after a gap analysis; it requested closure of the incident report.

Model: gpt-5.4-nano Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.90 5 comments
Chronology
  1. GlobalSign issued an organization-validated S/MIME certificate that later was found (via post-linter) to have an invalid Subject:organizationIdentifier structure for the NTR scheme.
  2. GlobalSign deployed a technical restriction in the vetting flow for NTR and European countries and revoked the affected certificate.
  3. GlobalSign deployed pkilint as a pre-linter in production and deployed additional technical restrictions in the vetting workflow.
  4. GlobalSign delivered training, completed remedial activities, and requested closure of the incident report.
Thread Activity
  1. GlobalSign nv-sa — Opened a preliminary incident report stating GlobalSign was notified by its post-linter about an invalid Subject:organizationIdentifier structure and planned to provide the full incident report by Feb 5, 2025.
  2. GlobalSign nv-sa — Provided the full incident report with impact, timeline, root cause, and completed/committed action items including revocation and vetting workflow changes.
  3. GlobalSign nv-sa — Updated that training was on track and asked to set the “Next Update” to Feb 21, 2025.
  4. GlobalSign nv-sa — Reported that training was delivered, pkilint was deployed as a pre-linter in production, gap analysis and additional technical restrictions were completed, and requested incident report closure.
  5. Mozilla representative — Stated an intention to close the bug on or about Feb 26, 2025 unless there were issues or questions.
Participants
GlobalSign nv-sa Mozilla representative
External References
Similar Local Cases
#1866806 RESOLVED Self Reported Incident Certificate Misissuance Opened 2023-11-27 · Closed 2024-02-01 · 97% similar
GlobalSign: S/MIME Sponsor validated certificates with CommonName value equal to OrganizationName
#1934790 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-12-03 · Closed 2025-01-14 · 96% similar
GlobalSign: OV TLS certificate with incorrect countryName value for organization
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 96% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1919304 RESOLVED Self Reported Incident Opened 2024-09-17 · Closed 2024-10-23 · 95% similar
GlobalSign: Caching headers inaccurate for subset of CRLs
#1917896 RESOLVED Self Reported Incident Opened 2024-09-10 · Closed 2025-03-18 · 93% similar
GlobalSign: Incorrect whois information for TLD
#1850091 RESOLVED Self Reported Incident Opened 2023-08-25 · Closed 2023-10-12 · 90% similar
GlobalSign: EV TLS certificate with only metadata in JOI State field
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 89% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1658932 RESOLVED Self Reported Incident Opened 2020-08-13 · Closed 2023-02-22 · 89% similar
GlobalSign: Incorrect Jurisdiction of Incorporation information for Japan

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action