NetLock intermediate certificates issued after 2019-01-01 without required EKU extension
This case concerns NetLock’s disclosure of three intermediate CA certificates issued after 2019-01-01 that did not comply with Mozilla Policy 2.6.1 because they lacked the required EKU extension. Ryan Sleevi opened the bug after a spot-check and listed the affected certificates on crt.sh. NetLock said it had identified the issue during an internal review on 2019-10-04, before the bug was filed, and that it had stopped issuing certificates with the problem. NetLock reported that it would replace the affected certificates, migrate end-entity certificates to new CAs, and add linting checks and process changes to prevent recurrence. The thread later records that the modified checking code went live on 2019-11-18, the affected CAs were replaced, and NetLock said the work was completed. Mozilla also discussed a separate delayed-revocation issue in the thread, but Ryan asked for that to be tracked in a separate bug.
- First affected intermediate certificate was issued without the required EKU extension.
- Last affected intermediate certificate was issued without the required EKU extension.
- NetLock identified the non-compliant issuance during an internal review.
- Mozilla filed the bug after discovering the issue in a spot-check.
- NetLock said modified checking code went live to block the error.
- NetLock said the affected CAs had been replaced and the work was completed.
- Community commenter — Ryan reported that NetLock had issued three intermediates after 2019-01-01 without an EKU extension and requested an incident report.
- Netlock — NetLock said it had identified the issue on 2019-10-04 during an ongoing audit, had opened internal JIRA tickets, and was replacing the certificates and migrating end-entity certificates.
- Fastly representative — Wayne asked why NetLock had failed to meet its earlier commitment to comply with the Mozilla change.
- Netlock — NetLock said the failure was due to human error and that it had added another CCADB contact person to improve its process.
- Netlock — NetLock proposed additional x509lint checks to block invalid EKU combinations in intermediates.
- Netlock — NetLock said the modified checking code would be in production on 2019-11-18.
- Netlock — NetLock gave a status update saying it had issued new certificates, fixed issuer software, and scheduled revocation and migration steps.
- Mozilla representative — Kathleen Wilson said the MKB SubCA 5 was ready to be added to OneCRL and confirmed the other two subCAs had been revoked.
- Community commenter — Ryan asked NetLock to file a separate bug for delayed revocation and to redo the incident report with more detail on the original failure.
- Netlock — NetLock said the remediation was completed and the affected CAs had been replaced.