Verify GlobalSign's continued conformance to EV guidelines
This case concerns GlobalSign's issuance of certificates that incorrectly included RFC1918 IP addresses, which do not comply with Extended Validation (EV) guidelines. The issue was raised following concerns about the verification process for domain ownership. GlobalSign acknowledged the problem, updated their policies to prevent future occurrences, and committed to revoking and replacing the affected certificates. The CA has since confirmed that all incorrectly issued certificates have been revoked and replaced. The case is now resolved, with the consensus that GlobalSign has taken appropriate actions to address the compliance issue.
- Initial concerns raised about GlobalSign's certificate issuance practices.
- GlobalSign confirmed the revocation and replacement of affected certificates.
- Kuix representative — Raised concerns about GlobalSign's verification of domain ownership for issued certificates.
- Mozilla representative — Noted that GlobalSign updated their issuance process to disallow RFC1918 IPs.
- GlobalSign nv-sa — Confirmed that affected certificates were revoked and replaced.
- Mozilla representative — Proposed closing the bug as resolved, fixed.