← Netlock cases
Bugzilla #1462423
Certificate Misissuance
NetLock: CN not in SAN
RESOLVED
FIXED
Netlock
AI Summary
NetLock issued seven pre-certificates where the Common Name (CN) did not match the Subject Alternative Name (SAN). This misissuance was reported by Andrew Ayer, leading to an investigation by NetLock. The CA acknowledged the issue, halted certificate issuance, and identified the root cause as a configuration error. They subsequently revoked the affected certificates and implemented new validation protocols to prevent future occurrences. An incident report was requested but initially not provided, leading to further follow-up from Mozilla representatives.
Chronology
- Issue reported by Andrew Ayer.
- Affected certificates revoked.
- NetLock submitted an incident report.
- Linting implementation completed.
Participants
Andrew Ayer
Varga Viktor
Wayne Thayer
Ryan Sleevi
Similar Local Cases
NetLock: Issuance of >398-day precertificates after 2020-09-01
NetLock: Non-BR-Compliant Certificate Issuance
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
Entrust: Certificate issued with validity greater than 825-days
certSIGN: "Some-State" in stateOrProvinceName
Kamu SM: "Some-State" in stateOrProvinceName
Hongkong Post / Certizen: Failure to report misissuance
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN