On 2024-06-29 19:45 UTC the below email was sent to 'szee@netlock.hu' - the contact listed in 1.5.2 of every one of NETLOCK's CP/S. No reply has been received within 24 hours. Below is a copy of the email for transparency: >Hello, > >This is the email listed in the current CPS covering the 'NetLock Arany (Class Gold) Fotanúsítvány' root. > >1: This is not listed on CCADB's Problem Reporting Mechanism's for NETLOCK which only provides: >- visszavonas[at]netlock[dot]hu >- https://netlock.hu >- compliance[at]netlock[dot]hu > >Neither email address appears in any CPS I can see - this needs corrected. > >2: This Certificate Problem Report has been filed due to a certificate failing both zlint and pkilint: >https://search.censys.io/certificates/51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496 > >$ lint_cabf_serverauth_cert lint -s ERROR -d 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem >SubscriberKeyUsageValidator @ certificate.tbsCertificate.extensions.1.extnValue.keyUsage > cabf.serverauth.subscriber_prohibited_ku_present (ERROR): Prohibited KU present: keyEncipherment >CertificatePolicyQualifierValidator @ certificate.tbsCertificate.extensions.5.extnValue.certificatePolicies.1.policyQualifiers.1 > cabf.serverauth.prohibited_certificate_policy_qualifier_type (ERROR): Prohibited qualifier type: 1.3.6.1.5.5.7.2.2 > >$ zlint 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem >e_ecdsa_allowed_ku, e_mp_ecdsa_signature_encoding_correct e_policy_qualifiers_other_than_cps_not_permitted > >Please note that zlint is reporting an additional error. > >- Wayne Now, finding out who to contact is an issue. The policy IDs listed in the certificate are generic, and the cpsuri gets redirected to [a very generic page](http://www.netlock.hu/html/dok.html). Checking just the Root isn't helpful as every CP/S mentions it. Luckily every CP/S has the same contact method listed for issues: >1.5.2. Contact person of the document The responsible contact person of the Policy Adopting Authority shall be the approver of the present document (see the cover page of the document). > >Customers, End Users and the Relying Parties may submit their questions and comments related to the present document to the NETLOCK Policy Adopting Authority in e-mail to szee@netlock.hu. As mentioned in the email... this isn't what is listed on CCADB, however the CP/S should be the authority relied on? Now figuring out which CP/S is applicable was a headache. Which is to say that having checked CCADB I do not believe this intermediary is disclosed. It also does not appear in a single CP/S directly. https://search.censys.io/certificates/d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419 CN: NETLOCK TLS OV ECC CA SHA256: d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419 Looking further this is at least a repeat of [#1889570](https://bugzilla.mozilla.org/show_bug.cgi?id=1889570) but for a freshly generated intermediary. Note that the undisclosed intermediary is different than the one stated in [#1904041](https://bugzilla.mozilla.org/show_bug.cgi?id=1904041). Given the naming scheme I would not be shocked at more undisclosed intermediaries, but I have also not checked. The lack of any obviously applicable CP/S for these intermediaries also raises a question I previously posed in [#1891331 Comment 28](https://bugzilla.mozilla.org/show_bug.cgi?id=1891331#c28). If no CP/S is covering these intermediaries and the CP/S isn't considered in-force until 30 days have past after the CP/S has been publicly published... what happens, and how do we tie a certificate to a CP/S? As I see it this is a certificate published that isn't tied to any CP/S, and is from an undisclosed intermediary. Please note this incident is purely for handling the lack of response from the CPR. Any other issue mentioned will need a separate incident raised by the CA.
Bug 1905509 Comment 0 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
On 2024-06-28 19:45 UTC the below email was sent to 'szee@netlock.hu' - the contact listed in 1.5.2 of every one of NETLOCK's CP/S. No reply has been received within 24 hours. Below is a copy of the email for transparency: >Hello, > >This is the email listed in the current CPS covering the 'NetLock Arany (Class Gold) Fotanúsítvány' root. > >1: This is not listed on CCADB's Problem Reporting Mechanism's for NETLOCK which only provides: >- visszavonas[at]netlock[dot]hu >- https://netlock.hu >- compliance[at]netlock[dot]hu > >Neither email address appears in any CPS I can see - this needs corrected. > >2: This Certificate Problem Report has been filed due to a certificate failing both zlint and pkilint: >https://search.censys.io/certificates/51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496 > >$ lint_cabf_serverauth_cert lint -s ERROR -d 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem >SubscriberKeyUsageValidator @ certificate.tbsCertificate.extensions.1.extnValue.keyUsage > cabf.serverauth.subscriber_prohibited_ku_present (ERROR): Prohibited KU present: keyEncipherment >CertificatePolicyQualifierValidator @ certificate.tbsCertificate.extensions.5.extnValue.certificatePolicies.1.policyQualifiers.1 > cabf.serverauth.prohibited_certificate_policy_qualifier_type (ERROR): Prohibited qualifier type: 1.3.6.1.5.5.7.2.2 > >$ zlint 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem >e_ecdsa_allowed_ku, e_mp_ecdsa_signature_encoding_correct e_policy_qualifiers_other_than_cps_not_permitted > >Please note that zlint is reporting an additional error. > >- Wayne Now, finding out who to contact is an issue. The policy IDs listed in the certificate are generic, and the cpsuri gets redirected to [a very generic page](http://www.netlock.hu/html/dok.html). Checking just the Root isn't helpful as every CP/S mentions it. Luckily every CP/S has the same contact method listed for issues: >1.5.2. Contact person of the document The responsible contact person of the Policy Adopting Authority shall be the approver of the present document (see the cover page of the document). > >Customers, End Users and the Relying Parties may submit their questions and comments related to the present document to the NETLOCK Policy Adopting Authority in e-mail to szee@netlock.hu. As mentioned in the email... this isn't what is listed on CCADB, however the CP/S should be the authority relied on? Now figuring out which CP/S is applicable was a headache. Which is to say that having checked CCADB I do not believe this intermediary is disclosed. It also does not appear in a single CP/S directly. https://search.censys.io/certificates/d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419 CN: NETLOCK TLS OV ECC CA SHA256: d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419 Looking further this is at least a repeat of [#1889570](https://bugzilla.mozilla.org/show_bug.cgi?id=1889570) but for a freshly generated intermediary. Note that the undisclosed intermediary is different than the one stated in [#1904041](https://bugzilla.mozilla.org/show_bug.cgi?id=1904041). Given the naming scheme I would not be shocked at more undisclosed intermediaries, but I have also not checked. The lack of any obviously applicable CP/S for these intermediaries also raises a question I previously posed in [#1891331 Comment 28](https://bugzilla.mozilla.org/show_bug.cgi?id=1891331#c28). If no CP/S is covering these intermediaries and the CP/S isn't considered in-force until 30 days have past after the CP/S has been publicly published... what happens, and how do we tie a certificate to a CP/S? As I see it this is a certificate published that isn't tied to any CP/S, and is from an undisclosed intermediary. Please note this incident is purely for handling the lack of response from the CPR. Any other issue mentioned will need a separate incident raised by the CA.