Netlock: Transition Plan for Existing Dual-Purpose Root
This case concerns NetLock’s NetLock Arany (Class Gold) Root CA, which is described as a legacy dual-purpose root trusted for both TLS and S/MIME. Mozilla Root Store Policy (MRSP) §7.5 requires separation of these trust purposes, and the incident report states that NetLock had not implemented technical trust bit separation or root replacement. The transition plan described in the thread relies on the root certificate’s natural expiration on 2028-12-06, which is stated to occur before the MRSP §7.5 compliance deadline of 2028-12-31. NetLock committed to not issuing new subordinate CA certificates or end-entity certificates that would extend reliance on this root beyond its validity period, and to allow existing usage to phase out naturally in alignment with the certificate’s expiration. Mozilla’s CA Program indicated that the plan satisfies the substantive requirements of MRSP §7.5 intent. The thread also notes that these “Transition Plan” bugs are intended for long-term tracking of root transition activities and are not compliance remediation bugs, and the parties agreed there is no need for updates unless the status or plans change.
- The root is described as operating as a dual-purpose (TLS and S/MIME) trust anchor.
- Non-compliance is described as being identified for the dual-purpose trust configuration relative to MRSP §7.5.
- Bug 2033033 is opened with a documented transition plan for the NetLock Arany (Class Gold) Root CA.
- The root certificate is scheduled to expire, ending the described reliance condition.
- The MRSP §7.5 compliance deadline is referenced in the incident report.
- Mozilla representative — Ben Wilson summarized NetLock’s transition plan as relying on the root’s natural expiration (2028-12-06) before the MRSP §7.5 deadline (2028-12-31) and stated no further trust-bit separation or root replacement is planned.
- Netlock — Roland Kaluha posted a full incident report describing the lack of trust-purpose separation, the reliance on natural expiration, and NetLock’s commitment to stop issuance that would extend reliance beyond the root’s validity.
- Netlock — Roland Kaluha stated NetLock does not intend to rely on the affected root beyond 2028-12-06 and therefore did not create a transition plan covering any period after the root’s expiration.
- Netlock — Roland Kaluha reported no changes and reiterated that mitigation remains based on natural expiration plus issuance restrictions.
- Netlock — Roland Kaluha provided an incident closure summary requesting closure of the bug.
- Netlock — Roland Kaluha acknowledged no changes and requested closure again.
- Netlock — Roland Kaluha reiterated the root’s scheduled expiration (2028-12-06) and requested closure.
- Netlock — Roland Kaluha stated there were no new developments and requested closure.
- Mozilla representative — Ben Wilson clarified that Transition Plan bugs are for long-term tracking and are not compliance remediation bugs, so they are intended to remain open for ongoing tracking.
- Netlock — Roland Kaluha acknowledged the clarification and agreed to proceed with long-term tracking expectations.