← Netlock cases
Bugzilla #2051459 Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Audit Delay

NETLOCK OCSP responder incident with separate CPR response-time and disclosure-process issues tracked in related bugs

ASSIGNED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This bug now tracks NETLOCK’s self-disclosed OCSP responder incident, not the separate CPR response-time failure. NETLOCK reported that a publicly trusted TLS certificate for nsi.netlock.hu was issued on 2026-06-05 but was not propagated to its OCSP responder infrastructure, causing the responder to return "unknown" until the responder was resynchronised on 2026-06-17. NETLOCK said it identified the non-compliance internally on 2026-06-16 through monitoring-analysis activities. The thread also records that the CPR response-time failure is being handled in Bug 2052541, and that the missed 72-hour preliminary disclosure was later filed as Bug 2063842. NETLOCK corrected earlier placeholders in its incident report, including the BR version, CP/CPS reference, and detection target, and added detection latency as a contributing factor. On 2026-08-15, NETLOCK confirmed that the separate Full Incident Report for the missed 72-hour preliminary-disclosure deadline had been filed as Bug 2063842. On 2026-10-01, NETLOCK said the Full Incident Report for the cadence failure was filed as Bug 2052541 Comment #15, and it also noted that a self-detected CRL publication defect found on 2026-09-26 may be covered by Bug 2075720 or may have needed its own report. The bug remains open and was last updated on 2026-10-01.

Model: gpt-5.4-mini Generated: 2026-07-04 18:22 UTC Revised: 2026-10-04 06:02 UTC Confidence: 0.97 22 comments
Chronology
  1. NETLOCK issued a publicly trusted TLS server certificate for nsi.netlock.hu.
  2. The issued certificate was not propagated to NETLOCK’s OCSP responder, which began returning an unknown status.
  3. NETLOCK identified the OCSP responder non-compliance through monitoring-analysis activities.
  4. The OCSP responder was resynchronised and the non-compliance ended.
  5. NETLOCK filed a Full Incident Report covering only the OCSP responder issue and said the CPR response-time failure was in Bug 2052541.
  6. CCADB staff renamed this bug as tracking the OCSP responder incident only and moved the CPR response-time incident to Bug 2052541.
  7. NETLOCK said the separate Full Incident Report for the missed 72-hour preliminary-disclosure deadline was filed as Bug 2063842.
  8. NETLOCK found a CRL publication defect while verifying the Gold hierarchy.
Thread Activity
  1. Community commenter — Opened the bug and reported both the OCSP availability failure and the separate failure to acknowledge the CPR within 24 hours.
  2. Netlock — Said this bug’s Full Incident Report covers only the OCSP responder issue and that the CPR response-time failure is addressed in Bug 2052541.
  3. Netlock — Clarified that the CPR-response failure is being tracked separately and discussed mailbox handling and Bugzilla awareness.
  4. Apple representative — Stated that the 24-hour CPR obligation runs from receipt of the CPR and that the late preliminary report was still not accounted for.
  5. CCADB representative — Renamed the bug to track the OCSP responder incident only and moved the CPR response-time incident to Bug 2052541.
  6. Netlock — Said NETLOCK still needed to confirm the BR version, CP/CPS reference, placeholder value N, and whether the detection/correction gap should be added to the root cause analysis.
  7. Netlock — Said NETLOCK was still looking into whether a 72-hour preliminary report was filed and the awareness-to-filing gap, and would respond in the next weekly update.
  8. CCADB representative — Noted that the report had gone stale and reminded NETLOCK that a Root Store Operator can set a Next update date.
  9. Netlock — Acknowledged that the report went stale and that the update was first posted to the wrong bug before being corrected.
  10. Netlock — Confirmed that Bug 2063842 was filed for the missed 72-hour preliminary-disclosure deadline and corrected the earlier explanation about the 72-hour control.
  11. Community commenter — Said the report appears to have gone stale because no extended update deadlines were applied for.
  12. Netlock — Said the report had gone stale, that weekly updates stopped after 2026-08-15, and that a separate incident report for the cadence failure would be filed by 2026-09-30.
  13. Netlock — Said the cadence-failure report was filed in Bug 2052541 Comment #15 and reported that a self-detected CRL publication defect may be covered by Bug 2075720 or may have needed its own report.
Participants
Community commenter Netlock Apple representative Thelettereph representative CCADB representative Mozilla representative
Similar Local Cases
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 96% similar
Netlock: CA in AIA in PEM format
#2004732 RESOLVED Ca Certificate Compliance Incident Opened 2025-12-08 · Closed 2026-01-05 · 92% similar
Certigna: AIA CA issuer field pointing to PEM encoded cert
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 91% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe
#2007116 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Ccadb Disclosure Issue Opened 2025-12-19 · Closed 2026-09-03 · 86% similar
D-Trust: CRL URL Disclosure
#2056942 RESOLVED Self Reported Incident Certificate Misissuance Audit Delay Audit Finding Opened 2026-07-22 · Closed 2026-09-23 · 85% similar
SDAIA: Missing S/MIME WebTrust audit coverage
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 85% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
#2011314 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-01-19 · Closed 2026-06-23 · 85% similar
Netlock: unspecifed revocation code (0) in CRL
#2052541 ASSIGNED Incident Self Reported Incident Problem Reporting Failure Remediation Tracking Opened 2026-07-03 Still Open · 84% similar
NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action