Netlock: Problem with NETLOCK's codesigning CA
NetLock reported that its CodeSign CA was found to be partially compliant with CSBR 2.3 Annex A based on the latest audit. The report stated that certificates issued after 1 June 2021, along with the corresponding root and intermediate certificates, were not compliant because the RSA modulus size was 2048 bits instead of 3072 bits. NetLock said it stopped issuance of code signing certificates immediately and decided to terminate code signing certificate issuance. NetLock later informed Mozilla that it had terminated its code signing business, meaning clients could no longer request issuance or renewal of code signing certificates. Mozilla closed the bug as invalid, stating that Mozilla no longer deals with the code signing trust bit. The thread does not describe any additional remediation beyond stopping and terminating code signing issuance.
- NetLock stopped issuing code signing certificates after an audit found non-compliance with CSBR 2.3 Annex A (RSA modulus size 2048 vs 3072).
- NetLock terminated its code signing business, preventing clients from requesting issuance or renewal of code signing certificates.
- Netlock — Created the bug and stated the latest audit showed NetLock CodeSign CA was partially compliant, with RSA modulus size 2048 bits instead of 3072 bits for certificates issued after 1 June 2021; issuance was stopped and termination steps were planned.
- Mozilla representative — Noted that the severity field was not set and asked for review.
- Netlock — Informed Mozilla that NetLock terminated code signing business and clients can no longer request issuance or renewal of code signing certificates.
- Mozilla representative — Closed the bug as invalid because Mozilla no longer deals with the code signing trust bit.