← Netlock cases
Bugzilla #1401211
Certificate Problem Report
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName
RESOLVED
FIXED
Netlock
AI Summary
NetLock reported a mis-issuance of a certificate that contained a wildcard character not in the leftmost position of the domain name. The issue was identified on September 2, 2017, following a user report. NetLock confirmed that they ceased issuing such certificates and implemented additional validation checks to prevent future occurrences. The root cause was attributed to human error during the editing of the certificate request. The certificate was revoked on September 12, 2017, after the customer completed their transition to a new certificate.
Chronology
- NetLock received a report about the mis-issuance.
- The problematic certificate was revoked.
- NetLock confirmed they stopped issuing non-compliant certificates.
- NetLock discussed their validation process improvements.
- Summary of issues and remediation plan was provided.
Participants
Varga Viktor
Gervase Markham
Ryan Sleevi
External References
Similar Local Cases
Consorci AOC: Non-BR-Compliant Certificate Issuance
Camerfirma: Non-BR-Compliant Certificate Issuance
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
Visa: Non-BR-Compliant Certificate Issuance
GoDaddy: New GoDaddy incorrect issuance bug appears to be regression of 2010 issue
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
DocuSign/Keynectis: Non-BR-Compliant OCSP Responders
Sectigo: invalid dnsName