← Netlock cases
Bugzilla #1824435
Certificate Problem Report
NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration)
RESOLVED
INVALID
Netlock
AI Summary
Netlock faced an issue with invalid Certificate Transparency (CT) data in certificates due to a misconfiguration with their SABRE CT log. The problem was identified after a customer reported an error in Chrome related to their certificate. Following the incident, Netlock ceased certificate issuance until the issue was resolved and notified affected subscribers. Ultimately, the case was marked as 'Invalid' as the inclusion of SCTs from an untrusted log was deemed non-compliant but not a violation of CA compliance.
Chronology
- Customer reported certificate error.
- Customer notification transferred to operations.
- Initial investigation started; CT problem identified.
- Subscribers notified of misissued certificates.
- Planned revocation of affected certificates.
Participants
Tamás Horváth
Rob from Sectigo
Andrew Ayer
B. Wilson
External References
Similar Local Cases
NETLOCK: Disclosed CRL is expired
NETLOCK: Pre-certificates revoked with certificateHold reason
NETLOCK: CRL Error on CRL Watch of NETLOCK DVCA CRL
Netlock: CA in AIA in PEM format
NETLOCK: SSL certificates with OU field
NETLOCK: SSL certificates with OU field - revocation delay
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName