← Netlock cases
Bugzilla #1676440 Ca Certificate Compliance Self Reported Incident

NetLock: Cumulative report connected to EV verification

RESOLVED FIXED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a cumulative incident report from NetLock related to EV validation and two specific certificate compliance problems. NetLock states that on 2020-11-26 Ben Wilson (EV validation) sent a list of possible validation problems; after questions were answered, two remaining problems were to be reported as incidents. For one issue, NetLock says BR certificates were required to be 398 days in validity or less, but in its DV system a 2-year (730-day) configuration was set to 365 days while one certificate request in progress kept the 2-year configuration, and the rule was lifted on 2020-09-01; NetLock reports that on 2020-09-29 certificates with more than 398 days were disabled from the PROD environment. For the second issue, NetLock says RSA keys must have a modulus size divisible by 8; it reports a DV certificate request with a 4092-bit key where the check did not give an error on renewal, and that after a 4096-bit key was generated a new certificate was issued and the faulty certificate was revoked (it also notes it is not possible to revoke a CT certificate, so that CT certificate remained valid). NetLock states it stopped issuing certificates with these problems and that it added new test cases and technical controls to make repeat errors impossible, with an update that blocking code was published in PROD on 2020-11-10. Mozilla’s Ryan Sleevi and Ben Wilson discussed the root cause focus on missing edge-case tests, and Ben Wilson indicated he would close the bug unless other items remained to discuss; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:04 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.86 7 comments
Chronology
  1. NetLock’s customer requested a DV certificate with a 4092-bit RSA key.
  2. NetLock’s DV system configuration for 2-year certificates was set to 365 days, but one in-progress request kept the 2-year CT certificate configuration.
  3. NetLock reports the 398-day validity rule was lifted.
  4. A customer continued ordering and attempted twice to proceed, resulting in CT certificate issuance.
  5. NetLock disabled issuance of SSL certificates with more than 398 days in the PROD environment.
  6. Ben Wilson reported the RSA modulus-size divisibility problem.
  7. NetLock temporarily blocked key sizes other than 2048 and 4096 bits; a new 4096-bit key was generated and a new certificate was issued, and the faulty certificate was revoked.
  8. NetLock published blocking code in the PROD environment and reports updates to fix the issues.
  9. Ben Wilson sent a list of possible EV validation problems, after which two remaining problems were to be reported as incidents.
  10. Ben Wilson indicated the bug should be closed with the understanding NetLock will stay on top of compliance and pre-issuance linting.
Thread Activity
  1. Netlock — NetLock opened the incident report describing two compliance problems, their timelines, affected CT certificate links, and remediation steps including new tests and technical controls.
  2. Fozzie representative — George asked whether case 1 was also covered in bug 1676367 and whether this bug should focus only on case 2.
  3. Community commenter — Ryan agreed the bug should cover case 2 and emphasized the need for systems thinking and root-cause analysis around missing tests.
  4. Netlock — NetLock explained that the original test plan assumed verified data and that the 8-divisibility check failed for renewals submitted before the check was deployed, with an update on 2020-11-10 and clarified test-case design guidance.
  5. Community commenter — Ryan stated the incident was preventable and assigned Ben Wilson to see if anything else could be added.
  6. Mozilla representative — Ben Wilson said he had nothing to add and believed the bug should be closed, expecting closure unless other items remained to discuss.
Participants
Netlock Fozzie representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 100% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 100% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1889570 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2024-04-04 · Closed 2024-08-28 · 89% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 87% similar
Netlock: CA in AIA in PEM format
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 87% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1716874 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-16 · Closed 2024-06-30 · 87% similar
NetLock: Intermediate CA Certificate Missing from Audit Reports
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 87% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action