Closed Bug 2058503 Opened 2 months ago Closed 1 month ago

GlobalSign: SubCA created with incorrect CPS Policy OID

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pki-notifications, Assigned: pki-notifications)

Details

(Whiteboard: [ca-compliance] [ca-misissuance])

Preliminary Incident Report

Summary

  • Incident description: During CCADB review GlobalSign has found that one SubCA (DHL Global TLS CA I6) has been created with incorrect CPS Policy OID
  • Relevant policies: CPS v10.6 section 1.2
  • Source of incident disclosure: Internal CCADB Review

We are currently investigating and will provide a full incident report by 2026-08-04

Assignee: nobody → pki-notifications
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [ca-misissuance]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000027
  • Incident description: GlobalSign has issued one CA certificate with CPS Policy OID 1.3.6.1.4.1.4146.1.2 (EV CodeSigning) instead of 1.3.6.1.4.1.4146.10.1.2 (OV TLS)
  • Timeline summary:
    • Non-compliance start date: Sep 17, 2025
    • Non-compliance identified date: Jul 28, 2026
    • Non-compliance end date: Aug 04, 2026
  • Relevant policies: GlobalSign CPS v10.6 section 1.2
  • Source of incident disclosure: Internal CCADB Review of CAs from July 2026 ceremony

Impact

  • Total number of certificates: 1
  • Total number of remaining valid certificates: 0, the affected CA has been revoked today
  • Affected certificate types: One TLS issuing CA
  • Incident heuristic: One Sub CA certificate contained an internal GlobalSign CPS Policy OID intended for EV Code Signing rather than the OV TLS CPS Policy OID documented for this issuing CA due to a missing .10 in the CPS Policy OID included in the certificate.
  • Was issuance stopped in response to this incident, and why or why not?: Yes. Issuance was stopped under the affected CA.
  • Analysis: The impact is limited to the DHL Global TLS CA I6 Sub CA certificate. Internal review of all Sub CA certificates confirmed this is the only affected certificate. The incorrect OID is documented in the CPS but is intended for EV Code Signing and not TLS. The affected Sub CA has been revoked within seven days of identification of issue.
  • Additional considerations: N/A

During the key ceremony held on 17 September 2025, GlobalSign created the DHL Global TLS CA I6 issuing CA:

https://crt.sh/?id=21199791366

The certificate was subject to the standard multi-person review process before release.

On 28 July 2026, during an internal CCADB review, GlobalSign identified that the CA certificate contained CPS Policy OID 1.3.6.1.4.1.4146.1.2 instead of the intended TLS CPS Policy OID 1.3.6.1.4.1.4146.10.1.2. The difference being the omission of .10 from the OID.

While the CA/B Forum Baseline Requirements permit non-BR policy OIDs when they are defined and documented by the CA in its Certificate Policy and/or Certification Practice Statement, the OID included in this certificate is documented for EV Code Signing use and was not intended for TLS issuance. Its inclusion in the DHL Global TLS CA I6 certificate was therefore an error.

Initial investigation indicates that the issue arose because both the manual review procedure and the supporting linting tools were primarily oriented around validating CA/B Forum policy OIDs. The review confirmed the presence and structure of the BR-related policy information, but did not verify that GlobalSign-specific CPS Policy OIDs matched the intended certificate type. As a result, the incorrect internal CPS Policy OID was not detected during the original creation and approval process.

GlobalSign also had a linting check in place as part of the CA review process. However, this check similarly focused on CA/B Forum policy OIDs and did not provide a programmatic comparison of internal CPS Policy OIDs against the expected profile for the specific CA type. This limitation meant that the missing .10 component in the TLS CPS Policy OID was not highlighted before the CA was released for setup.

Timeline

Date/Time (UTC) Description
2025-09-02 03:09 Pre-certificate of DHL Global TLS CA I6 and lint log submitted for review and approval
2025-09-02 05:01 Review and approval of new DHL Global TLS CA I6 completed
2025-09-17 02:55 DHL Global TLS CA I6 created
2025-09-19 11:06 DHL Global TLS CA I6 passes internal review and is released for setup
2026-07-28 07:34 During review of CAs created in July key ceremony it is noted that DHL Global TLS CA I6 is being ALV flagged for missing EV audit
2026-07-28 07:38 Upon review of DHL Global TLS CA I6 it is noted that the CA has Policy OID 1.3.6.1.4.1.4146.1.2 instead of 1.3.6.1.4.1.4146.10.1.2
2026-07-28 07:38 Policy OID issue escalated internally and review of other Sub CAs initiated
2026-07-29 09:54 Internal review of all Sub CA certificates confirms this to be the only affected certificate
2026-07-29 14:21 PM team coordinates stopping issuance from the affected Sub CA
2025-07-30 03:05 Pre-certificate of DHL Global TLS CA I7 and lint log submitted for review and approval
2025-07-30 05:01 Review and approval of new DHL Global TLS CA I7 completed
2026-08-03 02:30 Ceremony to create replacement Sub CA
2026-08-03 05:29 Review process completed for new DHL Global TLS CA I7 Sub CA
2026-08-03 17:43 Setup of replacement DHL Global TLS CA I7 Sub CA
2026-08-04 06:00 Revocation of affected Sub CA

Related Incidents

No related incidents were identified.

Root Cause Analysis

Contributing Factor #1: CA review and approval procedure does not have sufficient coverage for occurrences of missing mistakes within the CPS Policy of a CA certificate

  • Description: The CA review and approval procedure did not include sufficient checks to confirm that CPS Policy OIDs matched the intended CA certificate type.
  • Timeline: During the subsequent investigation from 2026-07-28 to 2026-07-29, we reviewed the CA creation and approval checklist and evidence from the 2025 reviews and confirmed that the manual review steps validated CA/B Forum policy OIDs but did not include an explicit verification that the GlobalSign CPS Policy OID matched the intended CA certificate type.
  • Detection: During review of the procedures followed during the approval of a Sub CA creation we identified that due to the fact that the approval process is a manual review there is cause for missing mistakes within a CPS OID within a CA certificate.
  • Interaction with other factors: Because the review procedure did not explicitly validate internal CPS Policy OIDs for the intended certificate type, the gap in linting/programmatic comparison was not compensated for by the manual review.
  • Root Cause Analysis methodology used: 5-Whys

Contributing Factor #2: Missing automated comparison / insufficient automated checks in place

  • Description: Although we did have linting in place, the output of which is used during pre and post issuance approval on all newly created CAs, this does not cover Internal Policy OIDs vs CA/B Forum policies.
  • Timeline: Linting was in place when DHL Global TLS CA I6 was created on 2025-09-17 and reviewed on 2025-09-02 and 2025-09-19.
  • Detection: While investigating the issue highlighted during review, we confirmed the issue with the linter scope.
  • Interaction with other factors: The absence of linting or programmatic comparison for internal Policy OIDs vs CA/B Forum OIDs meant that detection depended on the manual review procedure.
  • Root Cause Analysis methodology used: 5-Whys

Lessons Learned

  • What went well: We were able to identify the issue quickly upon certificate inspection.
  • What didn’t go well: A Sub CA was issued which incorporated an error.
  • Where we got lucky: Only one Sub CA certificate was affected by this defect.
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Add explicit verification of CPS OID to Sub CA certificate approval procedure Mitigate #1 The updated Sub CA certificate approval procedure requires explicit verification that each internal CPS Policy OID matches the intended CA certificate type before approval. Evidence: approved procedure update includes this checklist item. 2026-08-17 Ongoing
Add programmatic comparison of new CAs OIDs Prevent #2 New CA certificates are blocked from release unless an automated profile check confirms the internal CPS Policy OID matches the expected OID for the CA type (e.g. OV TLS = 1.3.6.1.4.1.4146.10.1.2). Evidence: successful tool output log attached for each new CA. 2026-08-17 Ongoing

We are on track with the delivery of both action items by 2026-08-17. We request that the next update is set to Tuesday 2026-08-18.

Whiteboard: [ca-compliance] [ca-misissuance] → Next update 2026-08-18 [ca-compliance] [ca-misissuance]

We completed the actions to add explicit verification of the CPS OIDs within the approval procedure and programmatic comparison of the OIDs on 2026-08-17.

This concludes the identified remedial activities. We will post a closure report by 2026-08-25.

Whiteboard: Next update 2026-08-18 [ca-compliance] [ca-misissuance] → [ca-compliance] [ca-misissuance]

Report Closure Summary

  • Incident description: GlobalSign issued one TLS Sub CA certificate with CPS Policy OID 1.3.6.1.4.1.4146.1.2 (EV CodeSigning) instead of 1.3.6.1.4.1.4146.10.1.2 (OV TLS).
  • Incident Root Cause(s): The CA creation review and approval procedure lacked sufficient checks to detect errors in a CA certificate’s CPS Policy OID, and no automated comparison was in place to identify such errors.
  • Remediation description: GlobalSign added explicit verification of CPS OID to the Sub CA certificate approval procedure and added programmatic comparison of new CA certificate's Policy OIDs to those listed in our CP/CPS.
  • Commitment summary: GlobalSign continues to identify opportunities to improve its internal processes by introducing automated checks.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-09-02.

Whiteboard: [ca-compliance] [ca-misissuance] → [close on 2026-09-02] [ca-compliance] [ca-misissuance]
Status: ASSIGNED → RESOLVED
Closed: 1 month ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-09-02] [ca-compliance] [ca-misissuance] → [ca-compliance] [ca-misissuance]
You need to log in before you can comment on or make changes to this bug.