NETLOCK: CRL not published in DER Encoded Format
NETLOCK reported a compliance issue regarding the encoding of Certificate Revocation Lists (CRLs) published in PEM format instead of the required DER format, violating RFC 5280. The issue was identified on December 17, 2024, and NETLOCK promptly changed the encoding format to DER on December 18, 2024. They confirmed that no subscribers were impacted by this issue, as the certificates were not malformed. NETLOCK has since implemented a new validation process to prevent future encoding errors, including the integration of a linter for ongoing compliance checks. All action items related to this incident have been completed, and NETLOCK has requested closure of the case.
- Notification received about improperly encoded CRLs.
- NETLOCK changed the CRL encoding from PEM to DER.
- Implementation of the pkimetal linter for validation completed.
- Netlock — Preliminary Incident Report submitted detailing the CRL encoding issue.
- Netlock — Incident Report submitted with further details and action items.
- Netlock — Request for closure submitted after completing all action items.