← Network Solutions cases
Bugzilla #1725039 Ca Certificate Compliance Self Reported Incident

Network Solutions: 2021 Audit Observation #1

RESOLVED FIXED Network Solutions
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Network Solutions' disclosure of a compliance issue identified during a 2021 audit, specifically regarding the absence of the Digital Signature bit in certain CA certificates used for direct OCSP signing. The issue was raised by Mozilla's Ben Wilson, leading to discussions about the implications of this oversight. Network Solutions argued that their practices were in line with pre-Baseline Requirements (BR) standards, but the conversation highlighted the need for compliance with current BRs. Ultimately, Network Solutions decided to transition to a managed CA model through Sectigo, ceasing the issuance of certificates under their own roots by November 2021.

Model: gpt-4o-mini Generated: 2026-06-13 21:05 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.85 24 comments
Chronology
  1. Bug reported regarding compliance issues with Network Solutions' CA certificates.
  2. Network Solutions completed transition to a managed CA model.
Thread Activity
  1. Mozilla representative — Raised concerns about Network Solutions CA certificates lacking the Digital Signature bit.
  2. Community commenter — Emphasized that using the root CA private key to sign OCSP responses without the Digital Signature bit constitutes an incident.
  3. Endurance representative — Announced the decision to transition to a managed CA model.
  4. Endurance representative — Confirmed completion of the transition to a managed CA model.
Participants
Mozilla representative Endurance representative Community commenter Sectigo Thisisntrocket representative
External References
Similar Local Cases
#1726333 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-08-18 · Closed 2023-02-22 · 100% similar
Network Solutions: All test CA test website certificates are expired
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 95% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 91% similar
Sectigo: Failure to provide timely incident reports
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 91% similar
Sectigo: CPR response issues
#1716163 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 91% similar
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
#1680378 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-12-02 · Closed 2023-02-22 · 87% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1672029 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-10-19 · Closed 2023-02-22 · 86% similar
Camerfirma: Failure to abide by Section 8 of Mozilla Policy: Unauthorized, improperly disclosed Subordinate CA
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 86% similar
IdenTrust: Undisclosed Unrevoked ICAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action