NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration)
Netlock reported that it had issued TLS server certificates containing invalid CT data due to a SABRE.CT misconfiguration. The issue was triggered when a customer notified Netlock on 21/03/2023 that their certificate produced an error in Chrome, and Netlock later identified the CT problem during initial investigation. Netlock stated that it contacted Google and Sectigo for explanations, identified all misissued certificates, notified subscribers, and stopped issuing certificates between identification of the issue and a CT service change from Sectigo to Cloudflare. Netlock also stated that all affected certificates would be renewed, and that it planned revocation for 28/03/2023. In the thread, Sectigo questioned whether this should be treated as a CA Compliance incident and noted concerns about the affected items and revocation reason usage. The bug was ultimately resolved as INVALID, with a later note that another bug (1830823) was created for the certificateHold revocation reason issue.
- A Netlock customer notified Netlock that a certificate produced an error in Chrome.
- Netlock began investigating and identified a CT problem; it contacted Google and Sectigo for explanations.
- Netlock sent subscriber notifications and identified misissued certificates.
- Netlock stated it would renew all certificates and discussed internal handling of the incident report.
- Netlock corrected the planned revocation date to 28/03/2023.
- Sectigo referenced a separate bug (1830823) created for the certificateHold revocation reason issue.
- Netlock — Reported that SABRE Trillian went live with a dodo private key and that issued certificates contained invalid CT data, and provided a timeline and affected crt.sh IDs.
- Sectigo — Asked why the reporter believed this was a CA Compliance incident and raised observations about precertificates vs final certificates and the revocation reason 'certificateHold'.
- Netlock — Responded that they decided to report it as an incident and would gather additional information.
- Netlock — Said the original timeline was incorrect and that the planned revocation date was 28/03/2023.
- Mozilla representative — Indicated the bug would be closed as 'Fixed' unless good reasons were provided to leave it open or close it differently.
- Mm representative — Argued the bug should be closed as 'Invalid' because SCTs from an untrusted log are not non-compliant, while noting the remaining 'certificateHold' revocation reason issue.
- Sectigo — Noted that since no NETLOCK incident bug was opened for the revocation reason issue, Mathew created bug 1830823.