← Netlock cases
Bugzilla #1676440 Policy Compliance

NetLock: Cumulative report connected to EV verification

RESOLVED FIXED Netlock
AI Summary

NetLock reported a cumulative incident related to Extended Validation (EV) certificate issuance. The issues involved two main cases: one concerning the validity period exceeding the maximum allowed days, and another regarding RSA key modulus size not being divisible by 8. Both problems were identified through internal audits and external reports, leading to immediate corrective actions. NetLock has since ceased issuing certificates with these issues and implemented new testing protocols to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:04 UTC Confidence: 0.90
Chronology
  1. DV system configuration set to 365 days instead of 398 days.
  2. Disabled issuance of SSL certificates exceeding 398 days.
  3. Blocked issuance of keys other than 2048 and 4096 bits.
  4. Published blocking code in production environment.
Participants
Varga Viktor Ben Wilson Ryan Sleevi
External References
Similar Local Cases
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 75% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 73% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1693930 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 56% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1907568 RESOLVED Policy Compliance Opened 2024-07-12 · Closed 2024-09-06 · 55% similar
NETLOCK: CPS 1.5.2. problem and contact information update
#1672029 RESOLVED Policy Compliance Opened 2020-10-19 · Closed 2023-02-22 · 54% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1664328 RESOLVED Policy Compliance Opened 2020-09-10 · Closed 2023-02-22 · 53% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key
#1650234 RESOLVED Policy Compliance Opened 2020-07-02 · Closed 2023-02-22 · 53% similar
PKIoverheid / QuoVadis: CPS inconsistencies
#1705904 RESOLVED Policy Compliance Opened 2021-04-17 · Closed 2023-02-22 · 53% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action