NETLOCK: SSL certificates with OU field - revocation delay
This case concerns a revocation delay for Netlock TLS server certificates that were affected by an earlier incident referenced in the bug. Netlock stated that the affected certificates were not revoked within the 5-day timeframe required by the BR because of a business decision based on customer requests. Netlock said it became clear on 10/03/2023 that it would not meet the 5-day revocation deadline, and it extended the revocation date; it also renewed all but one TLS certificate to remove the OU field. Netlock reported that it stopped certificate issuance right on the date the original notification was processed. The last certificate was revoked on 16/03/2023, and Netlock provided remediation steps including weekly checking of crt.sh statuses and work toward automated monitoring/linting, with monitoring implemented in backend software and additional Go-based linting planned. Mozilla asked for status updates on remediation efforts, and Netlock later reported that linting was implemented and an external monitoring tool (uptimerobot) was chosen and implemented, after which Mozilla indicated it would close the bug on 29-Sept-2023.
- Netlock extended the revocation date for affected TLS server certificates.
- All but one affected TLS certificate were renewed without an OU field.
- Netlock revoked the last remaining affected TLS certificate.
- Mozilla indicated it would close the bug.
- Netlock — Reported that affected certificates were not revoked within the BR timeframe due to customer requests, described the extended revocation timeline, and stated that only TLS server certificates were affected (4 total), with one certificate not yet revoked at that time.
- Netlock — Provided an attachment indicating the remaining certificates and stated that the last certificate was revoked that day.
- Google representative — Asked for reasons subscribers could not support the BR revocation timeline and requested elaboration on remediation actions with status and completion dates.
- Netlock — Explained that a client requested revocation only during their March 16 maintenance window and outlined remediation actions (weekly crt.sh checks and planned automated controls) with deadlines.
- Mozilla representative — Requested a status update on Netlock’s remediation efforts.
- Netlock — Reported that weekly manual checking was implemented and still in progress, requirements for automatic checks were defined, and implementation would not be completed by end of May.
- Netlock — Reported that monitoring (C-based linter) was implemented in backend software and that Go-based linting was planned for 31/08/2023.
- Netlock — Reported that linting was implemented, an external monitoring tool (uptimerobot) was chosen and implemented, and suggested the issue could be closed.
- Mozilla representative — Stated that Mozilla would close the bug on Friday, 29-Sept-2023.