NetLock: Cumulative report connected to EV verification
This case is a cumulative incident report from NetLock related to EV validation and two specific certificate compliance problems. NetLock states that on 2020-11-26 Ben Wilson (EV validation) sent a list of possible validation problems; after questions were answered, two remaining problems were to be reported as incidents. For one issue, NetLock says BR certificates were required to be 398 days in validity or less, but in its DV system a 2-year (730-day) configuration was set to 365 days while one certificate request in progress kept the 2-year configuration, and the rule was lifted on 2020-09-01; NetLock reports that on 2020-09-29 certificates with more than 398 days were disabled from the PROD environment. For the second issue, NetLock says RSA keys must have a modulus size divisible by 8; it reports a DV certificate request with a 4092-bit key where the check did not give an error on renewal, and that after a 4096-bit key was generated a new certificate was issued and the faulty certificate was revoked (it also notes it is not possible to revoke a CT certificate, so that CT certificate remained valid). NetLock states it stopped issuing certificates with these problems and that it added new test cases and technical controls to make repeat errors impossible, with an update that blocking code was published in PROD on 2020-11-10. Mozilla’s Ryan Sleevi and Ben Wilson discussed the root cause focus on missing edge-case tests, and Ben Wilson indicated he would close the bug unless other items remained to discuss; the bug is resolved as FIXED.
- NetLock’s customer requested a DV certificate with a 4092-bit RSA key.
- NetLock’s DV system configuration for 2-year certificates was set to 365 days, but one in-progress request kept the 2-year CT certificate configuration.
- NetLock reports the 398-day validity rule was lifted.
- A customer continued ordering and attempted twice to proceed, resulting in CT certificate issuance.
- NetLock disabled issuance of SSL certificates with more than 398 days in the PROD environment.
- Ben Wilson reported the RSA modulus-size divisibility problem.
- NetLock temporarily blocked key sizes other than 2048 and 4096 bits; a new 4096-bit key was generated and a new certificate was issued, and the faulty certificate was revoked.
- NetLock published blocking code in the PROD environment and reports updates to fix the issues.
- Ben Wilson sent a list of possible EV validation problems, after which two remaining problems were to be reported as incidents.
- Ben Wilson indicated the bug should be closed with the understanding NetLock will stay on top of compliance and pre-issuance linting.
- Netlock — NetLock opened the incident report describing two compliance problems, their timelines, affected CT certificate links, and remediation steps including new tests and technical controls.
- Fozzie representative — George asked whether case 1 was also covered in bug 1676367 and whether this bug should focus only on case 2.
- Community commenter — Ryan agreed the bug should cover case 2 and emphasized the need for systems thinking and root-cause analysis around missing tests.
- Netlock — NetLock explained that the original test plan assumed verified data and that the 8-divisibility check failed for renewals submitted before the check was deployed, with an update on 2020-11-10 and clarified test-case design guidance.
- Community commenter — Ryan stated the incident was preventable and assigned Ben Wilson to see if anything else could be added.
- Mozilla representative — Ben Wilson said he had nothing to add and believed the bug should be closed, expecting closure unless other items remained to discuss.