Closed Bug 1979287 Opened 1 year ago Closed 1 year ago

NETLOCK: Expired Test Website Certificate

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: kaluha.roland, Assigned: kaluha.roland)

Details

(Whiteboard: [ca-compliance] [policy-failure])

Dear Community Members,
we are filing the following preliminary incident report.

Summary

Incorrect publication of revoked test certificate on CA test website – NETLOCK

CA Name

NETLOCK Kft.

CA Certificate Subject

CN=NetLock Arany (Class Gold) Főtanúsítvány;
OU=Tanúsítványkiadók (Certification Services);
O=NetLock Kft.;
C=HU;
L=Budapest

Root Certificate

NetLock Arany (Class Gold)

Affected Certificate(s)

https://crt.sh/?q=6c1c17cdda6adb57dc6f061df1765ee6c019c798ea700123bb8fccf31008b859
Expired certificate currently served at: https://revoked.ev.tanusitvany.hu/

Issue Summary

This report identifies a non-conformance with the CA/Browser Forum Baseline Requirements related to test website obligations.
The test page listed in CCADB as hosting a revoked certificate currently serves a certificate that is expired instead of revoked.

Relevant Baseline Requirements Section

Section 2.2 – Publication of Information
The CA SHALL host test Web pages that allow Application Software Suppliers to test their software with Subscriber Certificates that chain up to each publicly trusted Root Certificate.
At a minimum, the CA SHALL host separate Web pages using Subscriber Certificates that are

  • valid
  • revoked
  • expired

Description of Non-Compliance

The CA’s test page for revoked certificates at https://revoked.ev.tanusitvany.hu/ currently serves an expired certificate instead of a revoked one.
This does not fulfill the requirement for a revoked certificate test case as defined in the Baseline Requirements.

Impact

Non-compliance with Baseline Requirements section 2.2
Potential disruption in testing environments for relying parties
Inaccurate representation of certificate status testing scenarios

Additional Notes

This issue was observed via CCADB and crt.sh
Other similar inconsistencies may exist but were not reviewed at this time

Reporter

Chrome Root Program on 2025-07-24

Assignee: nobody → kaluha.roland
Summary: NETLOCK - CA/Browser Forum TLS BR Non-compliance → NETLOCK: Expired Test Website Certificate
Whiteboard: [ca-compliance] [policy-failure]

Is there an update to this issue?

Dear Community Members,
in accordance with the applicable regulations, we will provide a more detailed update within 14 days following the preliminary report. We are planning to share this information by tomorrow.

1. Incident Summary

On 2025-07-24, the Chrome Root Program identified a compliance issue involving NETLOCK Kft.’s test webpage that was intended to host a revoked certificate. Instead, it was observed serving an expired certificate. This violates the CA/Browser Forum Baseline Requirements (BRs), specifically Section 2.2, which mandates that CAs must operate test pages hosting Subscriber Certificates in valid, revoked, and expired states.

2. Affected Party

CA Name:
NETLOCK Kft.

CA Certificate Subject:
CN=NetLock Arany (Class Gold) Főtanúsítvány
OU=Tanúsítványkiadók (Certification Services)
O=NetLock Kft.
C=HU
L=Budapest
Root Certificate:
NetLock Arany (Class Gold)

Test Website (revoked certificate):
https://revoked.ev.tanusitvany.hu/

Affected Certificate:
crt.sh record

3. Description of Non-Compliance

According to Section 2.2 – Publication of Information of the Baseline Requirements:

The CA SHALL host test Web pages that allow Application Software Suppliers to test their software with Subscriber Certificates that chain up to each publicly trusted Root Certificate. At a minimum, the CA SHALL host separate Web pages using Subscriber Certificates that are:

  • valid
  • revoked
  • expired

As of the date of observation, NETLOCK’s test webpage for revoked certificates was instead serving an expired certificate. This fails to meet the requirement for a test page dedicated to revoked certificates.

4. Timeline

Date Event
2025-07-24 Issue discovered by Chrome Root Program via CCADB and crt.sh
2025-07-24 NETLOCK internal investigation began
2025-07-25 Root cause identified
2025-07-25 Remediation plan implemented
2025-07-25 Correction verified and deployed
2025-07-30 Preventive measures finalized

5. Root Cause Analysis

The issue was caused by a misconfiguration in the staging and publishing workflow related to the test website content. The certificate intended for the revoked test page had expired; however, no automated mechanism was in place to verify that the appropriate certificate type (revoked, rather than expired) was being utilized.

The certificate was manually uploaded during routine maintenance of the test environment, but the revocation step was inadvertently omitted. As a result, a previously expired certificate remained active on the test page that was intended for validating revoked certificates.

Furthermore, the manual process lacked the required four-eyes principle verification step, which resulted in the oversight not being identified by our staff in a timely manner.

6. Remediation

As of 2025-07-25, NETLOCK has:

  • Removed the expired certificate from the affected test site.
  • Replaced it with a freshly issued and properly revoked certificate for compliance testing purposes.
  • Conducted a manual review of all other CCADB-listed test URLs to confirm they correctly reflect their intended certificate status (valid, revoked, or expired).
  • Verified through internal test requests that the corrected test page now serves a revoked certificate as required.

7. Preventive Measures

As of 2025-07-30, the following preventive measures have been finalized and implemented:

  • Mandatory four-eyes review prior to test site certificate deployment to catch omissions or misconfigurations.
  • Monitoring system that periodically scans test websites and flags any certificate status mismatches.
  • Internal compliance audit checklist updated to include routine validation of test pages listed in CCADB.
  • Version control and change logging mechanisms were reviewed and improved for test certificate deployment processes.

8. Impact

  • Non-compliance with Baseline Requirements Section 2.2
  • Potential misguidance of relying parties during revoked certificate handling tests
  • Risk of undermining confidence in the reliability of test environments hosted by the CA
  • Limited to test-only environment; no production certificates or relying parties were affected

9. Conclusion

NETLOCK acknowledges this non-conformity and has fully addressed the issue by investigating, remediating, verifying, and finalizing preventive controls. The CA remains committed to maintaining full compliance with CA/Browser Forum requirements and root store policies. No further action is pending regarding this incident.


Reporter: Chrome Root Program
Date of Observation: 2025-07-24
Date of Report: 2025-08-08
Reported by: NETLOCK Kft. – Compliance Team

Dear Community Members,
should you have any questions or comments regarding this ticket, we will be glad to provide clarification and respond accordingly.

Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true

Closure Summary

No questions or comments have been received regarding our report so far.

Incident description

This bug involved the NETLOCK test CA website serving an expired test certificate despite it being revoked, which violated policy expectations. The issue was identified following our report and was corrected.

Root cause analysis

Technical root cause
The expired certificate remained deployed on the test site due to an oversight in removal processes. Internal procedures did not ensure test environments were synchronized with revocation actions in a timely manner.

Organizational root cause
There were insufficient governance and monitoring controls to guarantee revocation enforcement across all environments, including staging and test. Responsibilities for synchronizing certificate removal were not clearly assigned.

Remediation actions

  • removed the expired certificate from the NETLOCK test site to ensure only active certificates are served
  • updated certificate publication protocols to include checks for expired or revoked certificates before deployment
  • implemented monitoring that flags any test or staging environment serving expired certificates

Impact

  • no expired or revoked certificates are currently being served
  • test and staging environments now reflect the same certificate status as production

Final status of action items

Action item Kind Status
remove expired certificate from test site repair completed
implement deployment checks for certificate validity prevent completed
establish monitoring for revoked/expired certificates in test envs prevent completed

Lessons learned

  • detection: checks now ensure expired or revoked certificates are caught before deployment
  • governance: process clarity has improved for managing certificate deployments across environments
  • preparedness: the organization is better equipped to avoid similar issues by enforcing environment parity and proactive monitoring

Commitment summary
NETLOCK regrets the oversight. Through enhancements in technical controls, operational processes, and governance, test environments are now aligned with revocation and certificate management standards. We request this bug be marked closed.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2025-08-29.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [policy-failure] → [close on 2025-08-29] [ca-compliance] [policy-failure]
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2025-08-29] [ca-compliance] [policy-failure] → [ca-compliance] [policy-failure]
You need to log in before you can comment on or make changes to this bug.