GlobalSign explained
GlobalSign is a certificate authority and a provider of internet identity and security products.[1] As of January 2015, Globalsign was the 4th largest certificate authority in the world, according to Netcraft.[2]
History
GlobalSign was founded in Belgium in 1996 and acquired in 2007 by GMO group in Japan (formerly GeoTrust Japan).[3]
In September 2011, as a precaution, GlobalSign suspended issuing authentication certificates temporarily after an anonymous hacker going by the name "ComodoHacker" claimed to have compromised their servers, as well as those of other certificate authorities.[4] The company took the claim seriously enough to halt the signing/issuing of new certificates while investigating the claims; it resumed issuing certificates a week later.[5] Dutch security company Fox-IT was contracted to analyze the breach and GlobalSign released a security incident report.[6] On December 13, 2011 GlobalSign released its final report on the incident.
The report concluded that while GlobalSign's own web server was breached and the certificate of this server was stolen, due to the air gap separating this web server from the certificate-issuing machine (the one holding the company's root certificate), there was no evidence of any rogue certificates issued or any customer data exposed, thus the remedial actions were limited to cancelling their own web server's certificate and patching its software. Sophos's Chester Wisniewski summarized the report and GlobalSign's response to the incident on his blog and concluded "Not only is the report thorough and convincing, but it appears that GlobalSign took every action, exactly as they should have, both during and after the incident."[7]
As of January 2015, Globalsign was the 4th largest certificate authority in the world according to the Netcraft survey. GlobalSign was the first CA to improve revocation checking for HTTPS pages through the use of a CDN,[8] and the company was also the first to offer IPv6 compliant revocation services ("CRL").[9]
In 2018, GlobalSign became a Qualified Trust Service Provider (QTSP) under the eIDAS regulation in both the European Union and the United Kingdom.[10] In 2021, after the UK left the EU, GlobalSign was approved as the UK's first QTSP.[11]
Services
GlobalSign's services include managed PKI platform, S/MIME certification, TLS certificates, and a cloud-based certificate manager that integrates with Microsoft's AD and user account certifications.[12]
The company also provides certificates to authenticate IoT to address authentication needs in the Internet of Everything (IoE) market and to identity management as a cloud-based service.[13] Its PKI services can scale based on the velocity, variety, and volume of IOT platforms, and can manage the identities of millions of devices.[14]
In November 2012, GlobalSign launched an online service that allows website administrators to confirm that they have correctly configured TLS across their websites and receive actionable guidance on how to remediate any faulty or exploitable TLS configurations.[15]
The company has offices in the US, Europe and throughout Asia.
In 2012, GlobalSign released its free SSL Configuration Checker.[16] [17] This tool lets websites check the effectiveness of their TLS configuration and provides remediation steps for websites that want to improve.[16] [18]
In 2013, the company introduced its Auto Enrollment Gateway solution (AEG).[19] Using AEG, companies can automate PKI management, certificate provisioning and deployment.[19] The platform integrates with Windows Active Directory.[19]
In 2018, GlobalSign released its IoT Identity Platform.[20] It uses PKI as its identity mechanism and is used in industries including manufacturing, agriculture, smart grid, payments, IoT gateways, and healthcare.[20] One of the features of the platform is IoT Edge Enroll, which companies use to provision and manage the PKI-based identities.[20] Edge Enroll provides device Registration Authority (RA), certificate lifecycle management and other support services.[21] The platform also includes IoT CA Direct and IoT CA Connect.[21]
In May 2022, the latest version of the company's AEG platform was released.[22] It automatically configures S/MIME certificates in Outlook for Windows using GlobalSign's cross-platform agent, XPA. XPA sets policies, and automatically enrolls, provisions, and installs certificates.
Acquisition
In 2014 GlobalSign acquired Helsinki-based Ubisecure Solutions, Inc., a privately held identity and access management (IAM) software developer.[23] Ubisecure was spun out of GlobalSign in 2016.[24] [25]
Industry Affiliations
- Certificate Authority/Browser Forum (CA/B Forum):[26] [27] GlobalSign is a founding member of the CA/B Forum, which was established in 2013. They are actively involved with the organization's S/MIME and server certificate working groups.
- Microsoft Intelligent Security Association (MISA): GlobalSign has been a member of MISA since 2019.[28]
- Cloud Signature Consortium: GlobalSign joined the consortium in 2018.[29]
- Certificate Authority Security Council (CASC) - joined in 2013.[27]
- Adobe Cloud Signature Partner Program[29]
See also
Notes and References
- Web site: GlobalSign and Infineon Join Forces to Strengthen IoT Trustworthiness . 2022-09-22 . www.iiotnewshub.com . en.
- Web site: SSL Survey. Netcraft. 2020-07-15. 2020-10-30. https://web.archive.org/web/20201030004525/https://www.netcraft.com/internet-data-mining/ssl-survey/. live.
- Web site: Outlook Series GlobalSign To Compete With VeriSign . 2022-10-06 . outlookseries.com . 2022-10-06 . https://web.archive.org/web/20221006203411/https://outlookseries.com/news/Services/1970.htm . live .
- https://www.bbc.co.uk/news/technology-14819257 BBC News - GlobalSign stops secure certificates after hack claim
- Web site: Whittaker . Zack . Unpatched server led to GlobalSign breach . ZDNet . 2020-09-09 . 2023-06-26 . https://web.archive.org/web/20230626035704/https://www.zdnet.com/article/unpatched-server-led-to-globalsign-breach/ . live .
- Web site: Steve Waite . 2011-12-13 . Security Incident Report . dead . https://web.archive.org/web/20190323041336/https://www.globalsign.com/en/resources/globalsign-security-incident-report.pdf . 2019-03-23.
- Web site: Chester Wisniewski . 2011-12-15 . Google and EFF propose improvements to HTTPS as GlobalSign releases CA breach report . 2012-08-14 . 2023-06-04 . https://web.archive.org/web/20230604042737/https://nakedsecurity.sophos.com/2011/12/15/google-and-eff-propose-improvements-to-https-as-globalsign-releases-ca-breach-report/ . live .
- Web site: CloudFlare Partners With GlobalSign To Make Loading Secure Web Pages Up To 6 Times Faster. TechCrunch (2012-11-01). Retrieved on 2013-07-26. . 2017-06-25 . 2023-06-06 . https://web.archive.org/web/20230606205822/https://techcrunch.com/2012/11/01/cloudflare-globalsign-make-ssl-faster/ . live .
- http://www.thewhir.com/web-hosting-news/globalsign-first-ca-to-offer-certificate-revocation-status-services-over-ipv6 GlobalSign First CA to Offer Certificate Revocation Status Services over IPv6
- Web site: Oct 22, 2018 . GlobalSign achieves Qualified Trust Service Provider Recognition in Europe . October 1, 2022 . October 1, 2022 . https://web.archive.org/web/20221001030144/https://hostingjournalist.com/globalsign-achieves-qualified-trust-service-provider-recognition-in-europe/ . live .
- Web site: July 28, 2021 . UK: ICO approves first UK eIDAS qualified trust service provider .
- Web site: Strom . David . 2022-05-19 . How to choose a certificate management tool . 2022-11-07 . CSO Online . en . 2022-11-07 . https://web.archive.org/web/20221107235855/https://www.csoonline.com/article/3660492/how-to-choose-a-certificate-management-tool.html . live .
- Web site: How to deal with IoT challenges through abstraction. 7 April 2016. 7 November 2022. 7 November 2022. https://web.archive.org/web/20221107235853/https://techcrunch.com/2016/04/06/how-to-deal-with-iot-challenges-through-abstraction/. live.
- Web site: Strom . David . 2022-05-19 . How to choose a certificate management tool . 2023-01-05 . CSO Online . en . 2022-12-02 . https://web.archive.org/web/20221202194142/https://www.csoonline.com/article/3660492/how-to-choose-a-certificate-management-tool.html . live .
- Web site: GlobalSign SSL Configuration Checker Provides Guidance to Reduce Cybercriminals' Ability to Exploit Faulty SSL Configurations . 2012-11-15 . 2017-01-15 . 2023-03-14 . https://web.archive.org/web/20230314204037/https://finance.yahoo.com/news/globalsign-ssl-configuration-checker-provides-130000642.html . live .
- Web site: Kovacs . Eduard . 2013-05-31 . 50% of Sites Using GlobalSign SSL Configuration Checker Improved Security in 30 Minutes or Less . 2022-11-14 . softpedia . english . 2022-11-14 . https://web.archive.org/web/20221114231300/https://news.softpedia.com/news/50-of-Sites-Using-GlobalSign-SSL-Configuration-Checker-Improved-Security-in-30-Minutes-or-Less-357348.shtml . live .
- Web site: admin . 2013-05-30 . GlobalSign Releases Findings of GlobalSign SSL Configuration Checker Evaluation for Q1 of 2013 . 2022-11-14 . Web Hosting Cloud Computing Datacenter Domain News . en-US . 2022-11-14 . https://web.archive.org/web/20221114231300/https://www.dailyhostnews.com/globalsign-releases-findings-of-globalsign-ssl-configuration-checker-evaluation-for-q1-of-2013 . live .
- Web site: admin . 2013-05-30 . GlobalSign Releases Findings of GlobalSign SSL Configuration Checker Evaluation for Q1 of 2013 . 2022-11-14 . Web Hosting Cloud Computing Datacenter Domain News . en-US . 2022-11-14 . https://web.archive.org/web/20221114231300/https://www.dailyhostnews.com/globalsign-releases-findings-of-globalsign-ssl-configuration-checker-evaluation-for-q1-of-2013 . live .
- Web site: Kovacs . Eduard . 2013-08-22 . GlobalSign Automates Management of Digital Certificates with Auto Enrollment Gateway . 2022-11-23 . softpedia . english . 2022-11-23 . https://web.archive.org/web/20221123044007/https://news.softpedia.com/news/GlobalSign-Automates-Management-of-Digital-Certificates-with-Auto-Enrollment-Gateway-377460.shtml . live .
- Web site: News . Industry . 2018-06-26 . GlobalSign launches IoT Identity Platform addressing IoT device security requirements . 2022-11-30 . Help Net Security . en-US . 2022-11-30 . https://web.archive.org/web/20221130000553/https://www.helpnetsecurity.com/2018/06/26/globalsign-iot-identity-platform/ . live .
- Web site: News . Industry . 2018-06-26 . GlobalSign launches IoT Identity Platform addressing IoT device security requirements . 2022-12-02 . Help Net Security . en-US . 2022-11-30 . https://web.archive.org/web/20221130000556/https://www.helpnetsecurity.com/2018/06/26/globalsign-iot-identity-platform/ . live .
- Web site: May 11, 2022 . GlobalSign Ready S/MIME feature enables users to secure email certificates . Help Net Security . December 21, 2022 . December 21, 2022 . https://web.archive.org/web/20221221183537/https://www.helpnetsecurity.com/2022/05/11/globalsign-aeg-7-5/ . live .
- Web site: greg . 2014-09-30 . Finland's Ubisecure acquired by GMO Globalsign for IoT Identity - ArcticStartup . 2022-11-14 . en-US . 2022-10-25 . https://web.archive.org/web/20221025220314/https://arcticstartup.com/finlands-ubisecure-acquired-by-gmo-globalsign-for-iot-identity/ . live .
- Web site: GlobalSign IAM is now Ubisecure Inc. November 30, 2016. June 18, 2020. March 14, 2023. https://web.archive.org/web/20230314173721/https://www.ubisecure.com/corporate/revealing-new-ubisecure/. live.
- Web site: greg . 2014-09-30 . Finland's Ubisecure acquired by GMO Globalsign for IoT Identity - ArcticStartup . 2022-10-25 . en-US . 2022-10-25 . https://web.archive.org/web/20221025214808/https://arcticstartup.com/finlands-ubisecure-acquired-by-gmo-globalsign-for-iot-identity/ . live .
- Web site: Members . 2022-12-15 . CAB Forum . en-US . 2015-01-24 . https://web.archive.org/web/20150124013021/https://cabforum.org/members/ . live .
- Web site: GlobalSign joins the Certificate Authority Security Council to upgrade internet security . 2022-12-15 . thepaypers.com . en . 2022-12-15 . https://web.archive.org/web/20221215195709/https://thepaypers.com/digital-identity-security-online-fraud/globalsign-joins-the-certificate-authority-security-council-to-upgrade-internet-security--750211 . live .
- Web site: Murphy . Ian . 2019-02-27 . GlobalSign joins Microsoft ISA for mobile security . 2022-12-15 . Enterprise Times . en-GB.
- Web site: Jacob . Marc . 2022-12-15 . GlobalSign rejoint le Cloud Signature Consortium et devient membre du programme de partenaires en signatures cloud Adobe . 2022-12-15 . Global Security Mag Online . fr.