Netlock delayed response to a Certificate Problem Report and later updated its CPR contact handling
This case concerns a Certificate Problem Report sent to Netlock on 2024-06-28 that was not answered within 24 hours. The reporter said the contact listed in Netlock’s CPS section 1.5.2 was used, and Netlock later acknowledged that the report was delivered but not responded to in time. Netlock’s initial incident report also described related certificate configuration issues, but the reporter asked that those be handled in separate bugs. Netlock later said it updated its CP/S contact information, trained staff, and implemented new procedures to improve triage and response handling. The bug was ultimately resolved as FIXED, and Netlock requested closure after submitting a closure summary.
- A Certificate Problem Report was sent to Netlock and was not answered within 24 hours.
- Netlock replied to the original email and said it would update Section 1.5.2.
- Netlock reported that its CP/S contact information had been updated and that affected certificates had been revoked.
- Netlock submitted a closure summary stating the CPR contact was now accurately disclosed and monitored.
- Community commenter — The reporter said no reply had been received within 24 hours and filed the bug about the missed CPR response.
- Internet Security Research Group — Aaron said the CCADB-disclosed CPR address is the relevant reporting mechanism and noted the CPS should describe it.
- DigiCert — Corey said BR 4.9.3 requires the CA’s problem reporting mechanism to be disclosed in CPS section 1.5.2.
- Netlock — Netlock said it would update Section 1.5.2 and that the CP/S change was in progress.
- Community commenter — The reporter confirmed receiving a reply and noted that a duplicate bug seemed to have been created.
- Netlock — Netlock filed an incident report describing the late response, the investigation, and the revocation of affected certificates.
- Netlock — Netlock restated that the email was not responded to within 24 hours and said the issue did not directly affect any certificate.
- Mozilla representative — Mozilla asked Netlock to submit a closure summary and formally request closure.
- Netlock — Netlock submitted a report closure summary and said all action items were completed.
- CCADB representative — CCADB issued a final call for comments and said the bug would be closed around 2025-05-08.