GlobalSign: StateOrProvince and LocalityName value inconsistency
This case concerns a Certificate Problem Report about a TLS certificate with an unexpected combination of StateOrProvince and LocalityName values. GlobalSign said the underlying values had been validated under CA/Browser Forum TLS Baseline Requirements section 3.2.2.1, but they were placed into the wrong fields: Philadelphia was entered as stateOrProvinceName and Pennsylvania as localityName. GlobalSign later reported that its investigation found 34 valid certificates across 14 subscribers with similar inconsistencies. The reported certificate was revoked, and GlobalSign said the additional affected certificates were revoked within the applicable timelines. GlobalSign also said it halted issuance for the affected profile, enabled daily reporting for review, and put additional measures in place to prevent re-issuance.
- Earliest affected certificate issued with inconsistent StateOrProvince and LocalityName values
- Reported TLS certificate issued
- Certificate Problem Report received for the affected certificate
- Reported certificate revoked
- Revocation of additional certificates identified in the review began and ended
- GlobalSign nv-sa — GlobalSign opened a preliminary incident report saying it had received a Certificate Problem Report and would provide a full incident report by 2026-08-28.
- GlobalSign nv-sa — GlobalSign said it was finalizing its investigation and expected to publish the full incident report by 2026-09-02.
- GlobalSign nv-sa — GlobalSign posted the full incident report, described the field-value inconsistency, listed 34 affected valid certificates, and said revocation and preventive measures had been carried out.