NETLOCK: Expired test website certificate served instead of revoked certificate
NETLOCK Kft. filed a preliminary incident report after identifying a non-conformance with CA/Browser Forum Baseline Requirements related to its test website obligations. The issue was that NETLOCK’s test page for revoked certificates (https://revoked.ev.tanusitvany.hu/) was serving an expired certificate rather than a revoked one, contrary to Baseline Requirements Section 2.2 (Publication of Information). NETLOCK stated that the problem was identified via CCADB and crt.sh, and that Chrome Root Program had identified the compliance issue on 2025-07-24. NETLOCK reported that it investigated the staging and publishing workflow misconfiguration, removed the expired certificate from the affected test site, and replaced it with a freshly issued and properly revoked certificate for compliance testing. NETLOCK also reported conducting a manual review of other CCADB-listed test URLs and verifying via internal test requests that the corrected test page now serves a revoked certificate. NETLOCK finalized preventive measures including a mandatory four-eyes review, monitoring to scan test websites for certificate status mismatches, and updates to an internal compliance audit checklist. The bug was resolved as FIXED, and NETLOCK requested closure after noting no questions or comments were received.
- Chrome Root Program identified that NETLOCK’s revoked test webpage was serving an expired certificate instead of a revoked one.
- NETLOCK removed the expired certificate from the revoked test site and deployed a properly revoked replacement after identifying the workflow misconfiguration.
- NETLOCK finalized preventive measures including four-eyes review and monitoring for certificate status mismatches.
- NETLOCK provided a closure summary and requested the bug be marked closed after no further comments were received.
- Netlock — Filed a preliminary incident report describing that the revoked test page served an expired certificate and citing Baseline Requirements Section 2.2.
- Cabbage representative — Asked whether there was an update to the issue.
- Netlock — Said NETLOCK would provide a more detailed update within 14 days and planned to share it by the next day.
- Netlock — Provided a detailed incident update including root cause, remediation steps (removal and replacement with a properly revoked certificate), and preventive measures (four-eyes review, monitoring, checklist updates, and improved version control).
- Netlock — Invited questions or comments regarding the ticket.
- Netlock — Submitted a closure summary stating no questions or comments were received and listing completed remediation and preventive actions.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2025-08-29 if no comments were received.