NETLOCK: Bug 1891331 replacement - delayed revocation -
This case involves NETLOCK's delayed revocation of TLS certificates that were issued with a deprecated 'explicitText' value in the User Notice extension, violating CA/Browser Forum Baseline Requirements (BRG 2.0). The issue was identified on April 3, 2024, prompting NETLOCK to initiate customer communication and plan for revocation. The CA revoked 522 affected certificates, with standard revocations completed by April 9, 2024, and additional revocations for critical customers completed by April 30, 2024. NETLOCK acknowledged that delays were inappropriate and has since revised its internal policies and subscriber contracts to ensure compliance with revocation timelines. The case is now resolved with all action items completed.
- NETLOCK notified of compliance issue with TLS certificates.
- Standard revocations completed for affected certificates.
- Delayed revocations for critical customers completed.
- Netlock — Opened a new ticket to summarize and address community questions regarding delayed revocation.
- Mozilla representative — Marked Bug 1891331 as a duplicate of this bug.
- Netlock — Acknowledged the need for compliance with revocation timelines and revised internal procedures.
- CCADB representative — Final call for comments or questions on this Incident Report.