← Netlock cases
Bugzilla #2051459 Self Reported Incident Incident Vulnerability Disclosure Remediation Tracking Opened By Ca

NETLOCK OCSP responder incident; separate 72-hour preliminary-disclosure failure now filed in Bug 2063842

ASSIGNED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This bug now tracks NETLOCK’s self-disclosed OCSP responder incident only. NETLOCK reported that a publicly trusted TLS certificate it issued for nsi.netlock.hu was not propagated to its OCSP infrastructure, causing the responder to return an "unknown" status until the responder was resynchronised. NETLOCK’s update says the non-compliance began on 2026-06-05, was identified internally on 2026-06-16, and ended on 2026-06-17. The thread also established that the separate Certificate Problem Report response-time issue is being handled in Bug 2052541, and the missed 72-hour preliminary-disclosure deadline has now been filed separately as Bug 2063842. NETLOCK later corrected placeholders in its incident report, including the detection target, BR version, and CP/CPS reference, and said it added detection latency as a contributing factor. The bug remains assigned, and the latest update says the separate preliminary-disclosure report has been filed.

Model: gpt-5.4-mini Generated: 2026-07-04 18:22 UTC Revised: 2026-08-16 06:01 UTC Confidence: 0.95 18 comments
Chronology
  1. NETLOCK issued a publicly trusted TLS server certificate for nsi.netlock.hu.
  2. The issued certificate was not propagated to NETLOCK’s OCSP responder, which began returning an unknown status.
  3. NETLOCK identified the OCSP responder non-compliance through monitoring-analysis activities.
  4. The OCSP responder was resynchronised and the non-compliance ended.
  5. NETLOCK filed a Full Incident Report covering only the OCSP responder issue and said the CPR response-time failure was in Bug 2052541.
  6. CCADB staff renamed this bug as tracking the OCSP responder incident only.
  7. NETLOCK said the separate Full Incident Report for the missed 72-hour preliminary-disclosure deadline was filed as Bug 2063842.
Thread Activity
  1. Community commenter — Opened the bug and reported both the OCSP availability failure and the separate failure to acknowledge the CPR within 24 hours.
  2. Netlock — Said this bug’s Full Incident Report covers only the OCSP responder issue and that the CPR response-time failure is addressed in Bug 2052541.
  3. Netlock — Clarified that the CPR-response failure is being tracked separately and discussed mailbox handling and Bugzilla awareness.
  4. Apple representative — Stated that the 24-hour CPR obligation runs from receipt of the CPR and that the late preliminary report was still not accounted for.
  5. CCADB representative — Renamed the bug to track the OCSP responder incident only and moved the CPR response-time incident to Bug 2052541.
  6. Netlock — Said NETLOCK still needed to confirm the BR version, CP/CPS reference, placeholder value N, and whether the detection/correction gap should be added to the root cause analysis.
  7. Netlock — Said NETLOCK was still looking into whether a 72-hour preliminary report was filed and the awareness-to-filing gap, and would respond in the next weekly update.
  8. CCADB representative — Noted that the report had gone stale and reminded NETLOCK that a Root Store Operator can set a Next update date.
  9. Netlock — Said the update was being posted in the correct bug, acknowledged the stale report and wrong-bug posting, and requested a Next update date.
  10. Netlock — Said the separate Full Incident Report for the missed 72-hour preliminary-disclosure deadline was filed as Bug 2063842 and corrected the earlier explanation about the 72-hour control.
Participants
Community commenter Netlock Apple representative Thelettereph representative CCADB representative Mozilla representative
Similar Local Cases
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 94% similar
Netlock: CA in AIA in PEM format
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 92% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 85% similar
Netlock: unspecifed revocation code (0) in CRL
#2052399 RESOLVED Incident Self Reported Incident Repository Issue Remediation Tracking Opened 2026-07-03 · Closed 2026-08-08 · 84% similar
Certainly: Expired certificates on "Valid" and "Revoked" test websites
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 84% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots
#2016585 RESOLVED Self Reported Incident Incident Opened 2026-02-12 · Closed 2026-06-15 · 84% similar
IdenTrust: Test Certificates from cross-signed roots not disclosed in CT Logs
#2013395 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-05-26 · 84% similar
NETLOCK: Missing Related Incidents section in the bug report
#2001327 RESOLVED Incident Revocation Issue Opened 2025-11-20 · Closed 2026-01-05 · 81% similar
NETLOCK: Missing CDP Disclosure in CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action