NETLOCK: Pre-certificates revoked with certificateHold reason
This case concerns NETLOCK pre-certificates being revoked using the revocation reason "certificateHold", which was described as forbidden by BR 7.2.2. The initial issue was reported in another bug (1824435), where NETLOCK was notified that one of their certificates was revoked with the incorrect certificateHold reason. NETLOCK later provided an incident report stating it first became aware of the problem via a customer notification on 21.03.2023 12:46, and that it opened bug 1824435 where Rob Stradling notified NETLOCK of the incorrect revocation reason. NETLOCK stated that it withdrew the certificateHold reason from the live site on 27/03/2023 and that it did not stop certificate issuance. NETLOCK also described process and software changes, including removing the certificateHold option from the online TLS administration interface (with a system update on 27/04/2023) and releasing a new interface version on 11/05/2023/28/07/2023 that removed the named reason and added new revocation reasons. The bug was resolved as FIXED, and Mozilla indicated it would close the ticket after checking for additional comments.
- NETLOCK received a customer notification about a certificate error in Chrome.
- NETLOCK was notified of the problem and began investigating.
- NETLOCK withdrew the "certificateHold" revocation reason from the live site.
- NETLOCK performed a system update removing the certificateHold option from the online TLS administration interface.
- NETLOCK released a new online TLS interface that does not include the named reason.
- NETLOCK reported the updated interface was released and that colleagues were trained.
- Community commenter — Created this bug for NETLOCK to respond, noting BR 7.2.2 forbids revocation reason "certificateHold" and asking whether NETLOCK was affected by the same EJBCA issue as other CAs.
- Sectigo — Commented that incident reports should be published within two weeks of the initial issue being reported and suggested NETLOCK needed an additional incident bug because the initial issue was reported nearly six weeks earlier.
- Netlock — Posted NETLOCK’s incident report, including when it became aware, a timeline of actions (including withdrawing the reason from the live site), and steps taken to prevent recurrence.
- Netlock — Updated the timeline to state that on 27/04/2023 a system update removed the certificateHold option and new revocation reasons were implemented.
- Netlock — Reported that the new online TLS version was released where certificateHold was removed and that internal process changes and training were implemented.
- Mozilla representative — Indicated Mozilla would close the ticket next week to check for any other comments.