← Netlock cases
Bugzilla #1824435 Certificate Problem Report

NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration)

RESOLVED INVALID Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Netlock reported that it had issued TLS server certificates containing invalid CT data due to a SABRE.CT misconfiguration. The issue was triggered when a customer notified Netlock on 21/03/2023 that their certificate produced an error in Chrome, and Netlock later identified the CT problem during initial investigation. Netlock stated that it contacted Google and Sectigo for explanations, identified all misissued certificates, notified subscribers, and stopped issuing certificates between identification of the issue and a CT service change from Sectigo to Cloudflare. Netlock also stated that all affected certificates would be renewed, and that it planned revocation for 28/03/2023. In the thread, Sectigo questioned whether this should be treated as a CA Compliance incident and noted concerns about the affected items and revocation reason usage. The bug was ultimately resolved as INVALID, with a later note that another bug (1830823) was created for the certificateHold revocation reason issue.

Model: gpt-5.4-nano Generated: 2026-06-13 21:04 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.50 9 comments
Chronology
  1. A Netlock customer notified Netlock that a certificate produced an error in Chrome.
  2. Netlock began investigating and identified a CT problem; it contacted Google and Sectigo for explanations.
  3. Netlock sent subscriber notifications and identified misissued certificates.
  4. Netlock stated it would renew all certificates and discussed internal handling of the incident report.
  5. Netlock corrected the planned revocation date to 28/03/2023.
  6. Sectigo referenced a separate bug (1830823) created for the certificateHold revocation reason issue.
Thread Activity
  1. Netlock — Reported that SABRE Trillian went live with a dodo private key and that issued certificates contained invalid CT data, and provided a timeline and affected crt.sh IDs.
  2. Sectigo — Asked why the reporter believed this was a CA Compliance incident and raised observations about precertificates vs final certificates and the revocation reason 'certificateHold'.
  3. Netlock — Responded that they decided to report it as an incident and would gather additional information.
  4. Netlock — Said the original timeline was incorrect and that the planned revocation date was 28/03/2023.
  5. Mozilla representative — Indicated the bug would be closed as 'Fixed' unless good reasons were provided to leave it open or close it differently.
  6. Mm representative — Argued the bug should be closed as 'Invalid' because SCTs from an untrusted log are not non-compliant, while noting the remaining 'certificateHold' revocation reason issue.
  7. Sectigo — Noted that since no NETLOCK incident bug was opened for the revocation reason issue, Mathew created bug 1830823.
Participants
Netlock Sectigo Mozilla representative Mm representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1830823 RESOLVED Delayed Revocation Opened 2023-05-02 · Closed 2023-08-04 · 51% similar
NETLOCK: Pre-certificates revoked with certificateHold reason
#1931615 RESOLVED Certificate Misissuance Opened 2024-11-15 · Closed 2024-12-03 · 48% similar
SSL.com: Entrust API and CAA checking
#1819105 RESOLVED Incident Opened 2023-02-27 · Closed 2023-09-29 · 48% similar
NETLOCK: Disclosed CRL is expired
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 47% similar
e-commerce monitoring GmbH: SCT in precertificate
#1896462 RESOLVED Certificate Problem Report Opened 2024-05-13 · Closed 2024-06-01 · 42% similar
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
#1822809 RESOLVED Delayed Revocation Opened 2023-03-16 · Closed 2023-09-29 · 42% similar
NETLOCK: SSL certificates with OU field - revocation delay
#1891331 RESOLVED Delayed Revocation Opened 2024-04-13 · Closed 2025-03-10 · 42% similar
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates - delayed revocation
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 42% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action