← Netlock cases
Bugzilla #1391056
Certificate Misissuance
NetLock: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Netlock
AI Summary
NetLock faced issues with the issuance of certificates that did not comply with the Baseline Requirements (BRs), specifically regarding invalid DNS names. The problems were identified after a customer reported issues with certificates containing accented characters. NetLock took immediate action to revoke the affected certificates and implemented measures to prevent future occurrences, including filtering for invalid characters in DNS names. The case highlights the importance of timely problem reporting and the need for robust validation processes.
Chronology
- Customer reported technical problem on Chrome 58.
- Filter for U-label DNS names implemented.
- Mozilla bug ticket received.
- Affected certificates revoked.
- Case marked resolved.
Participants
Kathleen Wilson
Varga Viktor
Gervase Markham
Jonathan Rudenberg
Ryan Sleevi
External References
Similar Local Cases
Disig: Non-BR-Compliant Certificate Issuance
NetLock: CN not in SAN
Microsec: Non-BR-Compliant Certificate Issuance
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
Amazon Trust Services: CAA Misissuances
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
SwissSign: Two certs issued with same issuer and serial number
SHA-1 issuance by DocuSign root