← Netlock cases
Bugzilla #2004699 Ca Certificate Compliance Incident Self Reported Incident Repository Issue Audit Document

Netlock incident: AIA CA Issuers endpoints served PEM-encoded CA certificates instead of DER

ASSIGNED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Netlock’s incident report about Authority Information Access (AIA) CA Issuers HTTP endpoints that returned issuer certificates in PEM format instead of the DER encoding required by RFC 5280 section 4.2.2.1. Netlock opened the bug after stating that the issue was identified through an external community report received on 2025-12-06. Netlock reported affected hierarchies including DVCA, trustev3, qtrustev3, and pdvca, and later acknowledged that an initial production deployment completed on 2026-01-08 did not fully resolve the problem because some endpoints were still serving PEM content. Netlock said remediation requires software changes because the affected URLs are generated by a publishing component in its certificate lifecycle and publishing infrastructure rather than by static files or simple web server configuration. The thread also includes repeated feedback from Apple, Mozilla, and community participants that Netlock’s handling of the Related Incidents section did not comply with CCADB Incident Reporting Guidelines; Netlock later said it opened a separate corresponding ticket and updated the related-incidents list in this bug. In the latest update, Netlock reported that one preventive action item was completed on 2026-07-15: after discussion with its auditor, audit procedures were updated so AIA CA Issuers endpoints are explicitly retrieved and their encoding verified during audit testing, with evidence retained. Netlock also published revised target dates of 2026-08-13 for the remaining open items: deploying the additional corrective fix and implementing automated AIA validation across affected publishing paths, including the previously reported ca=gold path, after which it plans to publish a closure summary. The bug remains open and assigned.

Model: gpt-5.4 Generated: 2026-06-13 21:03 UTC Revised: 2026-07-26 06:00 UTC Confidence: 0.96 43 comments
Chronology
  1. Non-compliant AIA configuration was introduced for the pdvca hierarchy.
  2. Non-compliant AIA configuration was introduced for the trustev3 and qtrustev3 hierarchies.
  3. Non-compliant AIA configuration was introduced for the DVCA hierarchy.
  4. Netlock said an external community report identified the AIA encoding non-compliance.
  5. Netlock said its initial production deployment was completed.
  6. Netlock staff and an external observer reported that some AIA endpoints were still serving PEM-encoded content.
  7. Netlock said testing identified and corrected an implementation defect, and re-testing began.
  8. Netlock said auditor procedures were updated so AIA CA Issuers endpoints are explicitly retrieved and their encoding verified during audit testing.
  9. Netlock set 2026-08-13 target dates for the additional corrective fix and automated AIA validation.
Thread Activity
  1. Netlock — Netlock opened the bug with a preliminary incident report stating that a third party had reported an AIA CA Issuers URI returning PEM content instead of DER.
  2. Community commenter — A community commenter said Netlock had not provided a satisfactory full incident report within 14 days and listed additional PEM-serving AIA URLs.
  3. Netlock — Netlock posted a full incident report describing affected hierarchies, dates, root causes, and a planned production release.
  4. Netlock — Netlock said demo validation had been completed and production deployment was still planned for 2026-01-09.
  5. Netlock — Netlock said production deployment had been completed on 2026-01-08 and that a closure summary would follow.
  6. Google representative — Google reported that several endpoints were still serving PEM-encoded certificates after the claimed deployment.
  7. Community commenter — A commenter said Netlock’s report did not follow CCADB incident-reporting guidance and included unsupported boilerplate claims.
  8. Apple representative — Apple asked Netlock to explain why similar prior bugs were not listed as related incidents and whether Netlock reviews other CAs’ incident reports.
  9. Netlock — Netlock updated its full incident report, acknowledged that PEM content was still being served from some endpoints, and added a second corrective-fix timeline.
  10. Netlock — Netlock said it limited Related Incidents to its own operations and described plans for an internal knowledge base.
  11. Apple representative — Apple said Netlock’s interpretation of Related Incidents was incompatible with the CCADB Incident Reporting Guidelines and requested a separate incident for that process non-compliance.
  12. Mozilla representative — Mozilla reiterated that Netlock should review public incident documentation from other CAs and file a separate incident report for the reporting non-compliance.
  13. Netlock — Netlock said it had opened the corresponding ticket to analyze and address the incident-reporting non-compliance referenced by the community.
  14. Netlock — Netlock posted updated action items and added a list of related incidents from other bugs.
  15. Netlock — Netlock explained that the remediation required a new software release because the affected URLs were generated by an integrated publishing component.
  16. Netlock — Netlock said testing had identified an implementation defect, that it had been corrected, and that re-testing was underway.
  17. Netlock — Netlock re-baselined its remaining action items, marking the additional corrective fix and automated validation as in progress with updated dates still to be determined.
  18. Netlock — Netlock said the corrected implementation remained under validation and preventive measures were progressing in parallel.
  19. Netlock — Netlock said no new blocking issues had been identified and that validation was ongoing.
  20. Netlock — Netlock said testing and verification continued and updated target dates would follow after validation and release planning.
  21. Netlock — Netlock said the remaining action items were still in progress and validation continued.
  22. Netlock — Netlock said there were no material changes and that validation and preventive actions remained underway.
  23. Netlock — Netlock said validation and release preparation for the remaining action items were ongoing.
  24. Netlock — Netlock said the additional corrective fix, automated AIA validation, and auditor-scope clarification were still in progress.
  25. Netlock — Netlock said no additional action item had been completed and that revised target dates for the remaining open items were still being finalized.
  26. Netlock — Netlock said another round of testing found no new defect, that remaining action items were still in progress, and that updated target dates and closure evidence were being prepared.
  27. Netlock — Netlock said no new issues had surfaced, the remaining action items were still in progress, and no additional action item had been completed during the latest reporting period.
  28. Netlock — Netlock reported that auditor-scope clarification was completed on 2026-07-15 and set 2026-08-13 target dates for the additional corrective fix and automated AIA validation.
Participants
Netlock Community commenter Google representative Apple representative Mozilla representative
Similar Local Cases
#2051459 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-06-30 Still Open · 100% similar
NETLOCK: OCSP Service Returning Error for Issued Certificate
#2007948 RESOLVED Self Reported Incident Incident Opened 2025-12-29 · Closed 2026-04-20 · 100% similar
NETLOCK: Full Incident Report was not published within 14 days of notification
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 100% similar
Netlock: unspecifed revocation code (0) in CRL
#2013395 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-05-26 · 100% similar
NETLOCK: Missing Related Incidents section in the bug report
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 100% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 95% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
#1950144 RESOLVED Incident Self Reported Incident Opened 2025-02-24 · Closed 2026-06-11 · 94% similar
DigiCert: Threat of legal action to stifle Bugzilla discourse
#2001327 RESOLVED Incident Revocation Issue Opened 2025-11-20 · Closed 2026-01-05 · 92% similar
NETLOCK: Missing CDP Disclosure in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action