NetLock: Non-BR-Compliant Certificate Issuance — wildcard not in the leftmost position in dnsName
This case reports NetLock’s mis-issuance of a TLS certificate containing an internal asterisk in a dnsName, where the wildcard was not in the leftmost position. NetLock stated it became aware of the issue on 2 September via an email about the mis-issuance of the certificate (crt.sh ID 201784770) and confirmed it had stopped issuing TLS/SSL certificates with the problem. NetLock explained that the mistake occurred on 16 August due to human error when a colleague edited the request to match corporate registry data and removed a separator, and that it was not caught during a second person’s check. NetLock said the affected customer requested not to revoke immediately to allow time to roll over the replacement certificate, and NetLock revoked the certificate on 12 September after replacement was reported. NetLock also described remediation steps, including implementing a second domain name validation check before issuance (added on 7 September) and stating that technical controls to validate domain data were implemented. Mozilla’s Ryan Sleevi summarized the issues and remediation plan and asked for confirmation; NetLock agreed the summary was correct, and the issue was considered resolved based on the provided information.
- NetLock issued a certificate with a wildcard/asterisk not in the leftmost position in the SAN dnsName.
- NetLock received an email notifying it of the mis-issuance and confirmed it had stopped issuing similar certificates.
- NetLock implemented an additional domain name validation check before certificate issuance.
- NetLock revoked the problematic certificate after the customer reported replacement.
- Mozilla reviewed NetLock’s remediation summary and indicated the issue would be called resolved based on the information provided.
- Community commenter — Varga Viktor reported the mis-issuance, described the root cause (human error removing a separator during request editing), stated NetLock stopped issuing similar certificates, and said the certificate was revoked on 12 September after customer rollover.
- Mozilla representative — Gerv asked whether NetLock planned to change a process that allows validation personnel to alter domain lists via a text editor and suggested adding cablint/certlint-style checks.
- Community commenter — Varga Viktor responded that validation personnel can edit only subject fields in NetLock’s CA software (not other certificate properties), described why edits are sometimes needed, and said NetLock added a second domain validation check and considered certlint/certlint-like approaches.
- Community commenter — Ryan Sleevi summarized the issue and remediation plan (including the wildcard leftmost-label problem and technical controls) and asked if the summary was correct.
- Community commenter — Varga Viktor confirmed Ryan’s summary was correct.