← Netlock cases
Bugzilla #1401211 Ca Certificate Compliance Certificate Misissuance

NetLock: Non-BR-Compliant Certificate Issuance — wildcard not in the leftmost position in dnsName

RESOLVED FIXED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports NetLock’s mis-issuance of a TLS certificate containing an internal asterisk in a dnsName, where the wildcard was not in the leftmost position. NetLock stated it became aware of the issue on 2 September via an email about the mis-issuance of the certificate (crt.sh ID 201784770) and confirmed it had stopped issuing TLS/SSL certificates with the problem. NetLock explained that the mistake occurred on 16 August due to human error when a colleague edited the request to match corporate registry data and removed a separator, and that it was not caught during a second person’s check. NetLock said the affected customer requested not to revoke immediately to allow time to roll over the replacement certificate, and NetLock revoked the certificate on 12 September after replacement was reported. NetLock also described remediation steps, including implementing a second domain name validation check before issuance (added on 7 September) and stating that technical controls to validate domain data were implemented. Mozilla’s Ryan Sleevi summarized the issues and remediation plan and asked for confirmation; NetLock agreed the summary was correct, and the issue was considered resolved based on the provided information.

Model: gpt-5.4-nano Generated: 2026-06-13 17:10 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.86 5 comments
Chronology
  1. NetLock issued a certificate with a wildcard/asterisk not in the leftmost position in the SAN dnsName.
  2. NetLock received an email notifying it of the mis-issuance and confirmed it had stopped issuing similar certificates.
  3. NetLock implemented an additional domain name validation check before certificate issuance.
  4. NetLock revoked the problematic certificate after the customer reported replacement.
  5. Mozilla reviewed NetLock’s remediation summary and indicated the issue would be called resolved based on the information provided.
Thread Activity
  1. Community commenter — Varga Viktor reported the mis-issuance, described the root cause (human error removing a separator during request editing), stated NetLock stopped issuing similar certificates, and said the certificate was revoked on 12 September after customer rollover.
  2. Mozilla representative — Gerv asked whether NetLock planned to change a process that allows validation personnel to alter domain lists via a text editor and suggested adding cablint/certlint-style checks.
  3. Community commenter — Varga Viktor responded that validation personnel can edit only subject fields in NetLock’s CA software (not other certificate properties), described why edits are sometimes needed, and said NetLock added a second domain validation check and considered certlint/certlint-like approaches.
  4. Community commenter — Ryan Sleevi summarized the issue and remediation plan (including the wildcard leftmost-label problem and technical controls) and asked if the summary was correct.
  5. Community commenter — Varga Viktor confirmed Ryan’s summary was correct.
Participants
Netlock Mozilla representative Community commenter
External References
Similar Local Cases
#1676367 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 98% similar
NetLock: Issuance of >398-day precertificates after 2020-09-01
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 97% similar
NetLock: CN not in SAN
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 88% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 86% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 85% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 80% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1734114 RESOLVED Certificate Misissuance Opened 2021-10-05 · Closed 2024-05-09 · 80% similar
Netlock: Problem with NETLOCK's codesigning CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action