← Netlock cases
Bugzilla #1979287 Incident

NETLOCK: Expired test website certificate served instead of revoked certificate

RESOLVED FIXED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NETLOCK Kft. filed a preliminary incident report after identifying a non-conformance with CA/Browser Forum Baseline Requirements related to its test website obligations. The issue was that NETLOCK’s test page for revoked certificates (https://revoked.ev.tanusitvany.hu/) was serving an expired certificate rather than a revoked one, contrary to Baseline Requirements Section 2.2 (Publication of Information). NETLOCK stated that the problem was identified via CCADB and crt.sh, and that Chrome Root Program had identified the compliance issue on 2025-07-24. NETLOCK reported that it investigated the staging and publishing workflow misconfiguration, removed the expired certificate from the affected test site, and replaced it with a freshly issued and properly revoked certificate for compliance testing. NETLOCK also reported conducting a manual review of other CCADB-listed test URLs and verifying via internal test requests that the corrected test page now serves a revoked certificate. NETLOCK finalized preventive measures including a mandatory four-eyes review, monitoring to scan test websites for certificate status mismatches, and updates to an internal compliance audit checklist. The bug was resolved as FIXED, and NETLOCK requested closure after noting no questions or comments were received.

Model: gpt-5.4-nano Generated: 2026-06-13 21:03 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.86 7 comments
Chronology
  1. Chrome Root Program identified that NETLOCK’s revoked test webpage was serving an expired certificate instead of a revoked one.
  2. NETLOCK removed the expired certificate from the revoked test site and deployed a properly revoked replacement after identifying the workflow misconfiguration.
  3. NETLOCK finalized preventive measures including four-eyes review and monitoring for certificate status mismatches.
  4. NETLOCK provided a closure summary and requested the bug be marked closed after no further comments were received.
Thread Activity
  1. Netlock — Filed a preliminary incident report describing that the revoked test page served an expired certificate and citing Baseline Requirements Section 2.2.
  2. Cabbage representative — Asked whether there was an update to the issue.
  3. Netlock — Said NETLOCK would provide a more detailed update within 14 days and planned to share it by the next day.
  4. Netlock — Provided a detailed incident update including root cause, remediation steps (removal and replacement with a properly revoked certificate), and preventive measures (four-eyes review, monitoring, checklist updates, and improved version control).
  5. Netlock — Invited questions or comments regarding the ticket.
  6. Netlock — Submitted a closure summary stating no questions or comments were received and listing completed remediation and preventive actions.
  7. CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2025-08-29 if no comments were received.
Participants
Netlock Cabbage representative CCADB representative
Similar Local Cases
#2001327 RESOLVED Incident Revocation Issue Opened 2025-11-20 · Closed 2026-01-05 · 97% similar
NETLOCK: Missing CDP Disclosure in CCADB
#2013395 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-05-26 · 95% similar
NETLOCK: Missing Related Incidents section in the bug report
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 95% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#1962426 RESOLVED Incident Opened 2025-04-24 · Closed 2025-07-16 · 90% similar
NETLOCK: CA/Browser Forum TLS BR Non-compliance
#1938167 RESOLVED Incident Opened 2024-12-18 · Closed 2025-06-10 · 88% similar
NETLOCK: CRL not published in DER Encoded Format
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 87% similar
Netlock: CA in AIA in PEM format
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 87% similar
Netlock: unspecifed revocation code (0) in CRL
#2007948 RESOLVED Self Reported Incident Incident Opened 2025-12-29 · Closed 2026-04-20 · 86% similar
NETLOCK: Full Incident Report was not published within 14 days of notification

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action