← Netlock cases
Bugzilla #1734114 Certificate Misissuance

Netlock: Problem with NETLOCK's codesigning CA

RESOLVED INVALID Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NetLock reported that its CodeSign CA was found to be partially compliant with CSBR 2.3 Annex A based on the latest audit. The report stated that certificates issued after 1 June 2021, along with the corresponding root and intermediate certificates, were not compliant because the RSA modulus size was 2048 bits instead of 3072 bits. NetLock said it stopped issuance of code signing certificates immediately and decided to terminate code signing certificate issuance. NetLock later informed Mozilla that it had terminated its code signing business, meaning clients could no longer request issuance or renewal of code signing certificates. Mozilla closed the bug as invalid, stating that Mozilla no longer deals with the code signing trust bit. The thread does not describe any additional remediation beyond stopping and terminating code signing issuance.

Model: gpt-5.4-nano Generated: 2026-06-13 21:04 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.50 4 comments
Chronology
  1. NetLock stopped issuing code signing certificates after an audit found non-compliance with CSBR 2.3 Annex A (RSA modulus size 2048 vs 3072).
  2. NetLock terminated its code signing business, preventing clients from requesting issuance or renewal of code signing certificates.
Thread Activity
  1. Netlock — Created the bug and stated the latest audit showed NetLock CodeSign CA was partially compliant, with RSA modulus size 2048 bits instead of 3072 bits for certificates issued after 1 June 2021; issuance was stopped and termination steps were planned.
  2. Mozilla representative — Noted that the severity field was not set and asked for review.
  3. Netlock — Informed Mozilla that NetLock terminated code signing business and clients can no longer request issuance or renewal of code signing certificates.
  4. Mozilla representative — Closed the bug as invalid because Mozilla no longer deals with the code signing trust bit.
Participants
Netlock Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1676367 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 87% similar
NetLock: Issuance of >398-day precertificates after 2020-09-01
#1401211 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-19 · Closed 2023-02-22 · 80% similar
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 78% similar
NetLock: CN not in SAN
#1777128 RESOLVED Certificate Misissuance Opened 2022-06-28 · Closed 2023-02-22 · 74% similar
GoDaddy: Misissuance of Cross Signed Certs
#1774171 RESOLVED Certificate Misissuance Opened 2022-06-14 · Closed 2023-02-22 · 74% similar
Certigna: Precertificate with a validity period greater than 398-days
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 70% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1732484 RESOLVED Certificate Misissuance Opened 2021-09-24 · Closed 2023-02-22 · 69% similar
Sectigo: Truncated registration numbers in EV certificates
#1463975 RESOLVED Certificate Misissuance Delayed Revocation Opened 2018-05-24 · Closed 2023-02-22 · 69% similar
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action