NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours, plus later update-cadence lapse
This case began as NETLOCK’s report that it failed to begin investigating and provide a preliminary response to a Certificate Problem Report within 24 hours, as required by CA/Browser Forum TLS Baseline Requirements Section 4.9.5. NETLOCK said the CPR was received at its disclosed problem-reporting address on 2026-06-10, but spam filtering and mailbox-handling issues kept it from reaching the compliance team in time. NETLOCK later implemented mail-system reconfiguration, alerting for messages routed to Junk or quarantine, and training so staff would treat CPRs arriving at any disclosed channel as CPRs and escalate them properly. In September, NETLOCK acknowledged that it also failed to keep its promised weekly update cadence on this bug and related incidents, and said it would file a separate Full Incident Report for that lapse. Mozilla said it will review NETLOCK’s past and current incidents and remediation evidence as part of its continued inclusion assessment, and the bug remains ASSIGNED.
- NETLOCK received a Certificate Problem Report at c**********o@netlock.hu.
- The 24-hour CPR response window expired without a preliminary report.
- NETLOCK’s compliance team became aware of the missed CPR response and began reviewing mail-system logs.
- NETLOCK completed mail system reconfiguration for c**********o@netlock.hu.
- NETLOCK said the CPR-recognition training material had been distributed and signed completion confirmations were collected.
- NETLOCK acknowledged that it had also failed to keep its promised update cadence.
- Netlock — Filed the full incident report describing the missed 24-hour CPR response and the mail-handling causes.
- Netlock — Said both action items remained on track for the committed due date of 2026-08-03.
- Netlock — Reported completion of the mail-system reconfiguration and said the training work remained in progress.
- Netlock — Said Action Item 2 was not yet complete, the 2026-08-03 date was missed, and the new target date was 2026-08-11.
- Community commenter — Said NETLOCK had not kept its promised weekly updates and asked Mozilla for a clear statement on future inclusion.
- Netlock — Acknowledged the seven-week silence, said Action Item 2 was complete, and said a separate Full Incident Report for the cadence failure would be filed by 2026-09-30.
- Mozilla representative — Said Mozilla will review NETLOCK’s past and current incidents and remediation evidence and then communicate its conclusion and any resulting action.
- Netlock — Filed a Full Incident Report covering the failure to maintain the committed update cadence on open compliance bugs, including this bug.