Bug 1905509 Comment 0 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

On 2024-06-29 19:45 UTC the below email was sent to 'szee@netlock.hu' - the contact listed in 1.5.2 of every one of NETLOCK's CP/S. No reply has been received within 24 hours. Below is a copy of the email for transparency:

>Hello,
>
>This is the email listed in the current CPS covering the 'NetLock Arany (Class Gold) Fotanúsítvány' root.
>
>1: This is not listed on CCADB's Problem Reporting Mechanism's for NETLOCK which only provides:
>- visszavonas[at]netlock[dot]hu
>- https://netlock.hu
>- compliance[at]netlock[dot]hu
>
>Neither email address appears in any CPS I can see - this needs corrected.
>
>2: This Certificate Problem Report has been filed due to a certificate failing both zlint and pkilint: >https://search.censys.io/certificates/51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496
>
>$ lint_cabf_serverauth_cert lint -s ERROR -d 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem
>SubscriberKeyUsageValidator @ certificate.tbsCertificate.extensions.1.extnValue.keyUsage
>    cabf.serverauth.subscriber_prohibited_ku_present (ERROR): Prohibited KU present: keyEncipherment
>CertificatePolicyQualifierValidator @ certificate.tbsCertificate.extensions.5.extnValue.certificatePolicies.1.policyQualifiers.1
>    cabf.serverauth.prohibited_certificate_policy_qualifier_type (ERROR): Prohibited qualifier type: 1.3.6.1.5.5.7.2.2
>
>$ zlint 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem
>e_ecdsa_allowed_ku, e_mp_ecdsa_signature_encoding_correct e_policy_qualifiers_other_than_cps_not_permitted
>
>Please note that zlint is reporting an additional error.
>
>- Wayne

Now, finding out who to contact is an issue. The policy IDs listed in the certificate are generic, and the cpsuri gets redirected to [a very generic page](http://www.netlock.hu/html/dok.html). Checking just the Root isn't helpful as every CP/S mentions it. Luckily every CP/S has the same contact method listed for issues: 
>1.5.2. Contact person of the document
The responsible contact person of the Policy Adopting Authority shall be the approver of the present document (see the cover page of the document).
>
>Customers, End Users and the Relying Parties may submit their questions and comments related to the present document to the NETLOCK Policy Adopting Authority in e-mail to szee@netlock.hu.

As mentioned in the email... this isn't what is listed on CCADB, however the CP/S should be the authority relied on?

Now figuring out which CP/S is applicable was a headache. Which is to say that having checked CCADB I do not believe this intermediary is disclosed. It also does not appear in a single CP/S directly.
https://search.censys.io/certificates/d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419
CN: NETLOCK TLS OV ECC CA
SHA256: d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419

Looking further this is at least a repeat of [#1889570](https://bugzilla.mozilla.org/show_bug.cgi?id=1889570) but for a freshly generated intermediary. Note that the undisclosed intermediary is different than the one stated in [#1904041](https://bugzilla.mozilla.org/show_bug.cgi?id=1904041). Given the naming scheme I would not be shocked at more undisclosed intermediaries, but I have also not checked.

The lack of any obviously applicable CP/S for these intermediaries also raises a question I previously posed in [#1891331 Comment 28](https://bugzilla.mozilla.org/show_bug.cgi?id=1891331#c28). If no CP/S is covering these intermediaries and the CP/S isn't considered in-force until 30 days have past after the CP/S has been publicly published... what happens, and how do we tie a certificate to a CP/S?

As I see it this is a certificate published that isn't tied to any CP/S, and is from an undisclosed intermediary.

Please note this incident is purely for handling the lack of response from the CPR. Any other issue mentioned will need a separate incident raised by the CA.
On 2024-06-28 19:45 UTC the below email was sent to 'szee@netlock.hu' - the contact listed in 1.5.2 of every one of NETLOCK's CP/S. No reply has been received within 24 hours. Below is a copy of the email for transparency:

>Hello,
>
>This is the email listed in the current CPS covering the 'NetLock Arany (Class Gold) Fotanúsítvány' root.
>
>1: This is not listed on CCADB's Problem Reporting Mechanism's for NETLOCK which only provides:
>- visszavonas[at]netlock[dot]hu
>- https://netlock.hu
>- compliance[at]netlock[dot]hu
>
>Neither email address appears in any CPS I can see - this needs corrected.
>
>2: This Certificate Problem Report has been filed due to a certificate failing both zlint and pkilint: >https://search.censys.io/certificates/51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496
>
>$ lint_cabf_serverauth_cert lint -s ERROR -d 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem
>SubscriberKeyUsageValidator @ certificate.tbsCertificate.extensions.1.extnValue.keyUsage
>    cabf.serverauth.subscriber_prohibited_ku_present (ERROR): Prohibited KU present: keyEncipherment
>CertificatePolicyQualifierValidator @ certificate.tbsCertificate.extensions.5.extnValue.certificatePolicies.1.policyQualifiers.1
>    cabf.serverauth.prohibited_certificate_policy_qualifier_type (ERROR): Prohibited qualifier type: 1.3.6.1.5.5.7.2.2
>
>$ zlint 51c3bd8e8aff40028016bd452405042ead0d8f64c1a2221df088cce5338d1496.pem
>e_ecdsa_allowed_ku, e_mp_ecdsa_signature_encoding_correct e_policy_qualifiers_other_than_cps_not_permitted
>
>Please note that zlint is reporting an additional error.
>
>- Wayne

Now, finding out who to contact is an issue. The policy IDs listed in the certificate are generic, and the cpsuri gets redirected to [a very generic page](http://www.netlock.hu/html/dok.html). Checking just the Root isn't helpful as every CP/S mentions it. Luckily every CP/S has the same contact method listed for issues: 
>1.5.2. Contact person of the document
The responsible contact person of the Policy Adopting Authority shall be the approver of the present document (see the cover page of the document).
>
>Customers, End Users and the Relying Parties may submit their questions and comments related to the present document to the NETLOCK Policy Adopting Authority in e-mail to szee@netlock.hu.

As mentioned in the email... this isn't what is listed on CCADB, however the CP/S should be the authority relied on?

Now figuring out which CP/S is applicable was a headache. Which is to say that having checked CCADB I do not believe this intermediary is disclosed. It also does not appear in a single CP/S directly.
https://search.censys.io/certificates/d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419
CN: NETLOCK TLS OV ECC CA
SHA256: d0eb908401f33242602634afd51991536b3ad7aa901586fdeb4955fe51b0e419

Looking further this is at least a repeat of [#1889570](https://bugzilla.mozilla.org/show_bug.cgi?id=1889570) but for a freshly generated intermediary. Note that the undisclosed intermediary is different than the one stated in [#1904041](https://bugzilla.mozilla.org/show_bug.cgi?id=1904041). Given the naming scheme I would not be shocked at more undisclosed intermediaries, but I have also not checked.

The lack of any obviously applicable CP/S for these intermediaries also raises a question I previously posed in [#1891331 Comment 28](https://bugzilla.mozilla.org/show_bug.cgi?id=1891331#c28). If no CP/S is covering these intermediaries and the CP/S isn't considered in-force until 30 days have past after the CP/S has been publicly published... what happens, and how do we tie a certificate to a CP/S?

As I see it this is a certificate published that isn't tied to any CP/S, and is from an undisclosed intermediary.

Please note this incident is purely for handling the lack of response from the CPR. Any other issue mentioned will need a separate incident raised by the CA.

Back to Bug 1905509 Comment 0