← Netlock cases
Bugzilla #2004699 Certificate Problem Report

Netlock: CA in AIA in PEM format

IN PROGRESS Netlock
AI Summary

Netlock has reported a compliance issue where several Authority Information Access (AIA) HTTP endpoints returned issuer certificates in PEM format instead of the required DER format, violating RFC 5280 Section 4.2.2.1. This non-compliance was identified through an external community report. Although the issue does not affect the issuance or validity of TLS certificates, it impacts relying parties that enforce DER encoding. Netlock has initiated remediation efforts, including a planned production release to correct the AIA endpoints by January 2026. However, concerns have been raised regarding the timeliness and effectiveness of their incident response and compliance practices.

Model: gpt-4o-mini Generated: 2026-06-13 21:03 UTC Confidence: 0.90
Chronology
  1. Non-compliant AIA configuration introduced for pdvca.
  2. Non-compliant AIA configuration introduced for trustev3 and qtrustev3.
  3. Non-compliant AIA configuration introduced for DVCA.
  4. External community report received identifying the AIA encoding non-compliance.
  5. Bugzilla bug filed by NETLOCK.
  6. Production deployment of initial corrective fix completed.
  7. Further issues identified with PEM encoding still being served.
  8. Development work for additional corrective fix initiated.
  9. Planned deployment of additional corrective fix.
Participants
Roland Kaluha Dean Reed Nikolette Nagy R. Daurne D. Hollenback B. Wilson
External References
Similar Local Cases
#2011314 ASSIGNED Certificate Problem Report Opened 2026-01-19 Still Open · 65% similar
Netlock: unspecifed revocation code (0) in CRL
#1824435 RESOLVED Certificate Problem Report Opened 2023-03-24 · Closed 2023-05-04 · 58% similar
NETLOCK: Invalid CT data in issued certs (SABRE.CT misconfiguration)
#2001327 RESOLVED Certificate Problem Report Opened 2025-11-20 · Closed 2026-01-05 · 56% similar
NETLOCK: Missing CDP Disclosure in CCADB
#2021559 RESOLVED Certificate Problem Report Opened 2026-03-06 · Closed 2026-05-28 · 55% similar
NETLOCK: Unavailability of the document repository
#1887941 RESOLVED Certificate Problem Report Opened 2024-03-26 · Closed 2024-06-01 · 53% similar
Actalis: revocation delay for certificates issued with invalid RDN Order
#1830823 RESOLVED Certificate Problem Report Opened 2023-05-02 · Closed 2023-08-04 · 51% similar
NETLOCK: Pre-certificates revoked with certificateHold reason
#1938167 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-06-10 · 51% similar
NETLOCK: CRL not published in DER Encoded Format
#1819105 RESOLVED Certificate Problem Report Opened 2023-02-27 · Closed 2023-09-29 · 50% similar
NETLOCK: Disclosed CRL is expired

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action