NETLOCK failed to file a preliminary incident report within 72 hours for an OCSP responder incident
This case concerns NETLOCK’s failure to file a preliminary incident report within 72 hours after becoming aware of a compliance incident involving an OCSP responder returning "unknown" for a validly issued certificate. NETLOCK says it learned of the issue through its own monitoring on 2026-06-16, making the preliminary report due by 2026-06-19, but no public report was filed by that deadline. The first public disclosure occurred later, on 2026-07-03 in Bug 2051459, and the thread explicitly treats that as a separate underlying incident report. The bug also distinguishes this disclosure-timeliness failure from the separate failure to acknowledge a Certificate Problem Report within 24 hours in Bug 2052541. In the latest comment, NETLOCK says it missed an interim-update target of 2026-08-31, repeated the same silence across three bugs for seven weeks, and plans to file a separate incident report about that cadence failure by 2026-09-30. The case remains ASSIGNED.
- NETLOCK became aware of an OCSP responder compliance incident through its own monitoring.
- The 72-hour preliminary incident report deadline passed without a public report.
- NETLOCK first publicly disclosed the incident in Bug 2051459.
- An interim-update target passed without the expected status update.
- Netlock — Opened the bug as a full incident report and said NETLOCK missed the 72-hour preliminary incident reporting deadline.
- Netlock — Explained that the underlying OCSP incident is tracked in Bug 2051459 and the separate 24-hour CPR response failure is tracked in Bug 2052541.
- Community commenter — Said the report appeared stale because no extended update deadlines were applied.
- Netlock — Acknowledged missing the interim-update target, said the same silence repeated across three bugs for seven weeks, and said a separate incident report for the cadence failure will be filed by 2026-09-30.