← GlobalSign nv-sa cases
Bugzilla #1393557
Certificate Problem Report
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign faced issues with the issuance of non-BR-compliant certificates, specifically RSA keys smaller than 2048 bits. The case was initiated due to a report highlighting these compliance failures. GlobalSign has since taken steps to address the situation, including moving AT&T to a hosted CA solution and implementing monthly audits of all issued certificates. The resolution involved a detailed remediation plan and regular updates to ensure compliance with the Baseline Requirements.
Chronology
- Initial report of non-compliance received.
- Status update on certificate issues provided.
- Summary of issues and remediation plan outlined.
- Transition to a hosted model confirmed, case closed.
Participants
Kathleen Wilson
Linus Hallberg
Douglas Beattie
Ryan Sleevi
Gervase Markham
External References
Similar Local Cases
GlobalSign: Non-BR-Compliant Certificate Issuance - metadata-only subject fields
GlobalSign: Non-BR-Compliant Certificate Issuance -- double-dots in dnsName
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
Consorci AOC: Non-BR-Compliant Certificate Issuance
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
GlobalSign: IP in dnsName
Visa: Non-BR-Compliant Certificate Issuance