← Netlock cases
Bugzilla #1586795 Policy Compliance

NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

RESOLVED FIXED Netlock
AI Summary

NetLock was found to have issued intermediate certificates after January 1, 2019, that did not comply with Mozilla Policy 2.6.1, specifically lacking the required Extended Key Usage (EKU) extension. Following the discovery of this issue, NetLock acknowledged the problem and initiated corrective actions, including the replacement of the non-compliant certificates and the implementation of new processes to prevent future occurrences. The CA has since confirmed that it is no longer issuing certificates with these issues and has completed the revocation of the affected certificates.

Model: gpt-4o-mini Generated: 2026-06-13 20:01 UTC Confidence: 0.95
Chronology
  1. NetLock identified non-compliant certificates during an internal audit.
  2. Ryan Sleevi reported the compliance issue to NetLock.
  3. NetLock revoked the old EV SSL certificates.
  4. NetLock revoked the old MKB SubCA certificate.
Participants
Ryan Sleevi Varga Viktor Wayne Thayer Ben Wilson Eszter Dolgos
External References
Similar Local Cases
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 77% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1676440 RESOLVED Policy Compliance Opened 2020-11-10 · Closed 2023-02-22 · 75% similar
NetLock: Cumulative report connected to EV verification
#1525082 RESOLVED Policy Compliance Opened 2019-02-04 · Closed 2022-11-14 · 60% similar
Ernst & Young Poland: KIR OCSP "unknown" status for revoked certificate
#1586787 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 60% similar
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1612389 RESOLVED Policy Compliance Opened 2020-01-30 · Closed 2023-02-22 · 57% similar
Google Trust Services: invalid curve-hash combination
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 57% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1907568 RESOLVED Policy Compliance Opened 2024-07-12 · Closed 2024-09-06 · 57% similar
NETLOCK: CPS 1.5.2. problem and contact information update
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 57% similar
GoDaddy: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action