← Netlock cases
Bugzilla #1938167 Certificate Problem Report

NETLOCK: CRL not published in DER Encoded Format

RESOLVED FIXED Netlock
AI Summary

NETLOCK faced an issue where Certificate Revocation Lists (CRLs) were published in PEM format instead of the required DER format, violating RFC 5280. This issue was reported on December 17, 2024, and confirmed the following day. NETLOCK quickly addressed the problem by changing the default encoding format to DER and replacing the affected CRLs. No impact on subscribers was identified, and all action items related to the incident have been completed, including the implementation of a validation process to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:03 UTC Confidence: 1.00
Chronology
  1. Notification received regarding improperly encoded CRLs.
  2. Confirmation of the issue and initiation of corrective actions.
  3. Completion of the integration process for the pkimetal linter.
  4. Final testing and production rollout of the linter completed.
Participants
nagy.nikolett@netlock.hu bugzilla@jesperkristensen.dk martijn.katerbarg@sectigo.com bwilson@mozilla.com
External References
Similar Local Cases
#1884461 RESOLVED Certificate Problem Report Opened 2024-03-08 · Closed 2024-05-20 · 56% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
#1744722 RESOLVED Certificate Problem Report Opened 2021-12-07 · Closed 2023-02-22 · 52% similar
FNMT: Invalid localityName
#1824435 RESOLVED Certificate Problem Report Opened 2023-03-24 · Closed 2023-05-04 · 52% similar
NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#1822809 RESOLVED Certificate Problem Report Opened 2023-03-16 · Closed 2023-09-29 · 52% similar
NETLOCK: SSL certificates with OU field - revocation delay
#1401211 RESOLVED Certificate Problem Report Opened 2017-09-19 · Closed 2023-02-22 · 52% similar
NetLock: Non-BR-Compliant Certificate Issuance -- * in not the leftmost position in dnsName
#1830823 RESOLVED Certificate Problem Report Opened 2023-05-02 · Closed 2023-08-04 · 51% similar
NETLOCK: Pre-certificates revoked with certificateHold reason
#1843173 RESOLVED Certificate Problem Report Opened 2023-07-12 · Closed 2023-09-29 · 51% similar
NETLOCK: CRL Error on CRL Watch of NETLOCK DVCA CRL
#2004699 ASSIGNED Certificate Problem Report Opened 2025-12-08 Still Open · 51% similar
Netlock: CA in AIA in PEM format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action