← Netlock cases
Bugzilla #1889570
Ca Certificate Compliance
Self Reported Incident
NETLOCK: Policy Qualifiers other than id-qt-cps is included in TLS certificates
RESOLVED
FIXED
Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
NETLOCK reported a compliance issue regarding TLS certificates that included policy qualifiers other than 'id-qt-cps', which is against the Baseline Requirements since September 15, 2023. The issue was identified on April 3, 2024, following a notification about a certificate failing a zlint check. NETLOCK initiated an investigation, communicated with affected customers, and planned the revocation of the misissued certificates. By May 1, 2024, all related certificates had been revoked, and NETLOCK has since improved its monitoring capabilities to prevent similar issues in the future.
Chronology
- NETLOCK was notified of a compliance issue with a TLS certificate.
- All related certificates were revoked.
Thread Activity
- Netlock — Initial investigation started after receiving a notification about a TLS certificate issue.
- Netlock — Detailed incident report provided, outlining the compliance failure and planned actions.
- Netlock — Confirmed that all related certificates have been revoked.
Participants
Netlock
Google representative
Community commenter
External References
Similar Local Cases
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
NetLock: Non-BR-Compliant Certificate Issuance
NetLock: Cumulative report connected to EV verification
NETLOCK: SSL certificates with OU field
NetLock: Intermediate CA Certificate Missing from Audit Reports
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
NETLOCK: Unavailability of the document repository
NETLOCK: Full Incident Report was not published within 14 days of notification