NetLock: Failure to revoke noncompliant ICA within 7 days
This case concerns NetLock’s missed timely revocation of noncompliant intermediate certificates (ICAs). Ryan Sleevi reported in ticket 1586795 that NetLock failed to revoke the problematic ICAs within the BR-specific deadline, and NetLock stated that the requirement change in the 2.7 Root Policy (effective 1 January 2020) was missed. NetLock reported receiving the original report on 2019-10-07 about intermediate certificates with missing EKUs, and it later revoked SSL ICAs on 2020-05-31 and the CA of digital signatures on 2020-06-30. NetLock attributed the delay to the revocation requirement not being implied under v2.6.1 and to the incident being handled in a different workflow, resulting in misalignment with the updated policy. NetLock described remediation steps including risk management software renewal, adding requirements aligned with ETSI EN/ISO 27000 and Mozilla root program requirements, raising administrative control and monitoring with additional compliance colleagues, and requesting its auditor partner to analyze the original problem and supervise implemented changes. The bug was resolved as FIXED, and Mozilla’s bwilson stated an intent to close the bug on or about 9 October 2020 unless further questions arose.
- NetLock received a report about intermediate certificates with missing EKUs.
- The 2.7 Root Policy revocation requirement became effective (as described by NetLock).
- NetLock revoked the SSL ICAs (as described by NetLock).
- NetLock revoked the CA of digital signatures (as described by NetLock).
- NetLock opened this bug to investigate the missed timely revocation.
- Mozilla indicated it would close the bug on or about 9 October 2020 unless additional questions arose.
- Netlock — NetLock explained that the 2.7 revocation requirement was missed after it became effective and provided a revocation timeline and certificate count (3).
- Netlock — NetLock responded to questions about awareness, actions taken, whether issuance stopped, problematic certificates (crt.sh links), and remediation steps (risk management renewal, compliance monitoring, auditor analysis).
- Community commenter — Ryan Sleevi asked for clarification on what changed and how it addresses systemic risks, noting concern about extended delays in revocation.
- Netlock — NetLock described contact changes and added compliance involvement, and said a supplement to its policy is in progress to focus on Mozilla Root Policy changes.
- Netlock — NetLock created an attachment describing a timeline and stating that separated/long processes missed red feedbacks and that compliance would monitor externally to IT.
- Mozilla representative — Mozilla stated it would close the bug on or about 9 October 2020 unless there were additional questions or issues.