NETLOCK failed to disclose four intermediate CA certificates to CCADB on time
NETLOCK reported that it had failed to disclose four newly issued intermediate CA certificates to CCADB within the required one-week period. The issue was first raised by NETLOCK in a preliminary incident report, and later community comments noted that the certificates remained undisclosed and that the incident report was not being updated promptly. NETLOCK said the problem involved confusion between cross-signed intermediates and the wrong root association during registration, which led to incorrect CCADB disclosure attempts. NETLOCK later stated that the affected intermediates were corrected and properly disclosed, and it filed a full incident report with a timeline, root cause analysis, and action items. The report also says NETLOCK introduced training, a six-eye review process, a CCADB checklist, and an internal checker tool to reduce the chance of recurrence. The bug was ultimately resolved with a closure summary stating that remediation actions were completed and that no mis-issuance or certificate misuse was found.
- NETLOCK began generating four affected intermediate CA certificates.
- The CCADB disclosure deadline for the certificates was missed.
- A third party informed NETLOCK of possible non-compliance.
- NETLOCK said all previously undisclosed intermediate certificates were corrected and properly disclosed in CCADB.
- NETLOCK posted an incident closure summary for the case.
- Netlock — NETLOCK opened the incident report and said it had failed to disclose a recently issued subordinate CA certificate to CCADB within one week.
- Sectigo — Rob Stradling said the certificates still had not been disclosed and asked when the CCADB disclosures would be completed.
- Mozilla representative — Ben Wilson asked why the intermediate CA certificates had not been uploaded to CCADB yet.
- Netlock — NETLOCK said it had disclosed the four intermediate certificates to CCADB and would open another ticket for a separate non-compliance issue.
- Google representative — Ryan Dickson said Netlock’s incident handling appeared concerning and asked for time-bound steps to improve reporting practices.
- Netlock — NETLOCK filed a full incident report describing the affected certificates, timeline, root cause, and action items.
- Netlock — NETLOCK posted an updated full incident report with a detailed timeline, root cause analysis, and corrective actions.
- Netlock — NETLOCK posted an incident closure summary stating that remediation actions were completed and the case was ready for closure.