← Netlock cases
Bugzilla #2052541 Incident Self Reported Incident Problem Reporting Failure Remediation Tracking Historical Reference

NETLOCK: Failure to Respond to a Certificate Problem Report Within 24 Hours, plus later update-cadence lapse

ASSIGNED Netlock
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case began as NETLOCK’s report that it failed to begin investigating and provide a preliminary response to a Certificate Problem Report within 24 hours, as required by CA/Browser Forum TLS Baseline Requirements Section 4.9.5. NETLOCK said the CPR was received at its disclosed problem-reporting address on 2026-06-10, but spam filtering and mailbox-handling issues kept it from reaching the compliance team in time. NETLOCK later implemented mail-system reconfiguration, alerting for messages routed to Junk or quarantine, and training so staff would treat CPRs arriving at any disclosed channel as CPRs and escalate them properly. In September, NETLOCK acknowledged that it also failed to keep its promised weekly update cadence on this bug and related incidents, and said it would file a separate Full Incident Report for that lapse. Mozilla said it will review NETLOCK’s past and current incidents and remediation evidence as part of its continued inclusion assessment, and the bug remains ASSIGNED.

Model: gpt-5.4-mini Generated: 2026-07-04 18:22 UTC Revised: 2026-10-04 06:02 UTC Confidence: 0.97 10 comments
Chronology
  1. NETLOCK received a Certificate Problem Report at c**********o@netlock.hu.
  2. The 24-hour CPR response window expired without a preliminary report.
  3. NETLOCK’s compliance team became aware of the missed CPR response and began reviewing mail-system logs.
  4. NETLOCK completed mail system reconfiguration for c**********o@netlock.hu.
  5. NETLOCK said the CPR-recognition training material had been distributed and signed completion confirmations were collected.
  6. NETLOCK acknowledged that it had also failed to keep its promised update cadence.
Thread Activity
  1. Netlock — Filed the full incident report describing the missed 24-hour CPR response and the mail-handling causes.
  2. Netlock — Said both action items remained on track for the committed due date of 2026-08-03.
  3. Netlock — Reported completion of the mail-system reconfiguration and said the training work remained in progress.
  4. Netlock — Said Action Item 2 was not yet complete, the 2026-08-03 date was missed, and the new target date was 2026-08-11.
  5. Community commenter — Said NETLOCK had not kept its promised weekly updates and asked Mozilla for a clear statement on future inclusion.
  6. Netlock — Acknowledged the seven-week silence, said Action Item 2 was complete, and said a separate Full Incident Report for the cadence failure would be filed by 2026-09-30.
  7. Mozilla representative — Said Mozilla will review NETLOCK’s past and current incidents and remediation evidence and then communicate its conclusion and any resulting action.
  8. Netlock — Filed a Full Incident Report covering the failure to maintain the committed update cadence on open compliance bugs, including this bug.
Participants
Netlock Community commenter Mozilla representative Lpch-intranet representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2063842 ASSIGNED Incident Self Reported Incident Problem Reporting Failure Remediation Tracking Opened 2026-08-15 Still Open · 89% similar
NETLOCK: Failure to file a preliminary incident report within 72 hours (OCSP responder incident, Bug 2051459)
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 85% similar
Netlock: CA in AIA in PEM format
#2051459 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-30 Still Open · 84% similar
NETLOCK: OCSP Service Returning Error for Issued Certificate
#2062162 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Opened By Subscriber Or Relying Party Opened 2026-08-10 · Closed 2026-09-20 · 78% similar
HARICA: TLS server certificate issuance against CP/CPS
#2061907 RESOLVED Ca Certificate Compliance Incident Problem Reporting Failure Information Request Opened 2026-08-08 · Closed 2026-08-26 · 77% similar
Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
#2032468 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-04-16 · Closed 2026-08-09 · 77% similar
VISA: Misissuance detected by PKIMetal
#2013395 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-05-26 · 76% similar
NETLOCK: Missing Related Incidents section in the bug report
#2013400 RESOLVED Self Reported Incident Incident Opened 2026-01-29 · Closed 2026-04-17 · 76% similar
NETLOCK: did not file a preliminary incident report or respond to a third-party report within the 72-hour timeframe

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action