Netlock incident: CRL entries encoded with explicit unspecified revocation reasonCode
This case concerns Netlock’s incident report about CRL entries that explicitly encoded X.509v3 CRL Reason Code “Unspecified” (value 0) in a published CRL. Netlock said the issue was first reported by an external third party on 2026-01-12, and that the affected entries were generated when certificates were suspended, not reactivated, and then automatically revoked after the suspension period expired. In its full incident report, Netlock said the non-compliance affected certificates revoked on or after 2023-07-15 and related to CRL generation logic rather than certificate issuance or certificate validity. Netlock identified the root cause as inconsistencies in the automated revocation workflow and insufficient validation of CRL output for this state transition. The thread also records discussion about Netlock’s delayed incident reporting, which Netlock acknowledged as separate incident-reporting non-compliance and said was documented in bug 2013400. Netlock reported that development changes were completed, internal testing found and corrected additional inconsistencies, and the corrected implementation was deployed to production on 2026-04-20. On 2026-06-12, Netlock said extended post-deployment validation had concluded without additional inconsistencies, all disclosed action items were complete, and it requested closure. The bug is now closed as RESOLVED FIXED.
- Netlock said the non-compliance began affecting certificates revoked on or after this date.
- A third party reported that Netlock’s CRL contained entries with explicit unspecified reasonCode values.
- Netlock said incident investigation started.
- Netlock said root cause was identified and investigation closed.
- Netlock said the issue was handed over to the development team.
- Netlock reported that the corrected implementation had been deployed to production.
- Netlock reported post-deployment validation had concluded without additional inconsistencies and requested closure.
- The bug was closed as RESOLVED FIXED.
- Netlock — Netlock opened the bug with a preliminary incident report describing an externally reported CRL reasonCode compliance issue.
- Community commenter — A commenter said the issue had first been reported to Netlock on 2026-01-12 and criticized Netlock’s delayed preliminary filing.
- Netlock — Netlock said it had begun reviewing the issue, was preparing updated training materials, and would provide a full incident report.
- CCADB representative — CCADB said comment 1 appeared to show Netlock had not met the 72-hour incident reporting expectation and noted a second report should be filed if Netlock agreed.
- Netlock — Netlock agreed it had not fully adhered to the CCADB Incident Reporting Guidelines and said it would file a second incident report about that non-compliance.
- Netlock — Netlock posted its full incident report, including impact, timeline, and root cause analysis.
- Community commenter — A commenter asked why the full incident report was posted after the 14-day deadline and whether a new incident would be raised for that non-compliance.
- Netlock — Netlock said the delayed preliminary report was recorded in bug 2013400 and attributed the later full-report timing issue to incorrect tracking-system configuration.
- Community commenter — A commenter challenged Netlock’s explanation of how the 14-day reporting clock was calculated.
- Netlock — Netlock said an incorrect start date in its tracking system caused deadline calculations to be based on the wrong reference time and said the configuration had been corrected.
- Community commenter — A commenter said Netlock had provided contradictory written interpretations of the reporting timeline.
- Netlock — Netlock said there was no discrepancy between its action items and prior explanation because the wrong reference date had been recorded.
- Community commenter — A commenter again asked Netlock to explain how its two timeline formulations were the same.
- Netlock — Netlock said its intended practice was to create a bug ticket immediately on external notification and calculate both T+72h and T+14d from that same T day.
- Netlock — Netlock said development changes for CRL reasonCode handling were complete and under internal testing.
- Netlock — Netlock said testing was still in progress for automatically revoked certificates following suspension.
- Netlock — Netlock said testing had found and corrected inconsistencies and that updated fixes were under further validation.
- Community commenter — A commenter asked Netlock to update outdated action items with current status and due dates.
- Netlock — Netlock posted updated remediation action items, including validation, deployment, post-deployment verification, and monthly revalidation.
- Netlock — Netlock said final validation was ongoing and deployment preparation continued.
- Netlock — Netlock said internal testing and validation had finished successfully and deployment was planned for that week.
- Netlock — Netlock said the corrected implementation had been deployed to production and post-deployment testing was in progress.
- Netlock — Netlock said the fix was deployed and post-deployment checks were continuing.
- Netlock — Netlock said no new issues had been identified during ongoing post-deployment verification.
- Netlock — Netlock said verification remained ongoing and no new inconsistencies had been found.
- Netlock — Netlock said continued checks had revealed no new issues.
- Netlock — Netlock said there had been no material change and verification was still ongoing.
- Netlock — Netlock said monitoring continued and no new issues were found during the reporting period.
- Netlock — Netlock posted a closure summary stating the fix was deployed, extended validation had concluded without additional inconsistencies, and all action items were complete.
- CCADB representative — CCADB issued a final call for comments and said the incident would otherwise be closed around 2026-06-19.
- Netlock — Netlock requested closure if there were no further comments.
- The bug status changed to RESOLVED with resolution FIXED.