NETLOCK: Expired Test Website Certificate
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: kaluha.roland, Assigned: kaluha.roland)
Details
(Whiteboard: [ca-compliance] [policy-failure])
Dear Community Members,
we are filing the following preliminary incident report.
Summary
Incorrect publication of revoked test certificate on CA test website – NETLOCK
CA Name
NETLOCK Kft.
CA Certificate Subject
CN=NetLock Arany (Class Gold) Főtanúsítvány;
OU=Tanúsítványkiadók (Certification Services);
O=NetLock Kft.;
C=HU;
L=Budapest
Root Certificate
NetLock Arany (Class Gold)
Affected Certificate(s)
https://crt.sh/?q=6c1c17cdda6adb57dc6f061df1765ee6c019c798ea700123bb8fccf31008b859
Expired certificate currently served at: https://revoked.ev.tanusitvany.hu/
Issue Summary
This report identifies a non-conformance with the CA/Browser Forum Baseline Requirements related to test website obligations.
The test page listed in CCADB as hosting a revoked certificate currently serves a certificate that is expired instead of revoked.
Relevant Baseline Requirements Section
Section 2.2 – Publication of Information
The CA SHALL host test Web pages that allow Application Software Suppliers to test their software with Subscriber Certificates that chain up to each publicly trusted Root Certificate.
At a minimum, the CA SHALL host separate Web pages using Subscriber Certificates that are
- valid
- revoked
- expired
Description of Non-Compliance
The CA’s test page for revoked certificates at https://revoked.ev.tanusitvany.hu/ currently serves an expired certificate instead of a revoked one.
This does not fulfill the requirement for a revoked certificate test case as defined in the Baseline Requirements.
Impact
Non-compliance with Baseline Requirements section 2.2
Potential disruption in testing environments for relying parties
Inaccurate representation of certificate status testing scenarios
Additional Notes
This issue was observed via CCADB and crt.sh
Other similar inconsistencies may exist but were not reviewed at this time
Reporter
Chrome Root Program on 2025-07-24
Updated•1 year ago
|
Dear Community Members,
in accordance with the applicable regulations, we will provide a more detailed update within 14 days following the preliminary report. We are planning to share this information by tomorrow.
1. Incident Summary
On 2025-07-24, the Chrome Root Program identified a compliance issue involving NETLOCK Kft.’s test webpage that was intended to host a revoked certificate. Instead, it was observed serving an expired certificate. This violates the CA/Browser Forum Baseline Requirements (BRs), specifically Section 2.2, which mandates that CAs must operate test pages hosting Subscriber Certificates in valid, revoked, and expired states.
2. Affected Party
CA Name:
NETLOCK Kft.
CA Certificate Subject:
CN=NetLock Arany (Class Gold) Főtanúsítvány
OU=Tanúsítványkiadók (Certification Services)
O=NetLock Kft.
C=HU
L=Budapest
Root Certificate:
NetLock Arany (Class Gold)
Test Website (revoked certificate):
https://revoked.ev.tanusitvany.hu/
Affected Certificate:
crt.sh record
3. Description of Non-Compliance
According to Section 2.2 – Publication of Information of the Baseline Requirements:
The CA SHALL host test Web pages that allow Application Software Suppliers to test their software with Subscriber Certificates that chain up to each publicly trusted Root Certificate. At a minimum, the CA SHALL host separate Web pages using Subscriber Certificates that are:
- valid
- revoked
- expired
As of the date of observation, NETLOCK’s test webpage for revoked certificates was instead serving an expired certificate. This fails to meet the requirement for a test page dedicated to revoked certificates.
4. Timeline
| Date | Event |
|---|---|
| 2025-07-24 | Issue discovered by Chrome Root Program via CCADB and crt.sh |
| 2025-07-24 | NETLOCK internal investigation began |
| 2025-07-25 | Root cause identified |
| 2025-07-25 | Remediation plan implemented |
| 2025-07-25 | Correction verified and deployed |
| 2025-07-30 | Preventive measures finalized |
5. Root Cause Analysis
The issue was caused by a misconfiguration in the staging and publishing workflow related to the test website content. The certificate intended for the revoked test page had expired; however, no automated mechanism was in place to verify that the appropriate certificate type (revoked, rather than expired) was being utilized.
The certificate was manually uploaded during routine maintenance of the test environment, but the revocation step was inadvertently omitted. As a result, a previously expired certificate remained active on the test page that was intended for validating revoked certificates.
Furthermore, the manual process lacked the required four-eyes principle verification step, which resulted in the oversight not being identified by our staff in a timely manner.
6. Remediation
As of 2025-07-25, NETLOCK has:
- Removed the expired certificate from the affected test site.
- Replaced it with a freshly issued and properly revoked certificate for compliance testing purposes.
- Conducted a manual review of all other CCADB-listed test URLs to confirm they correctly reflect their intended certificate status (valid, revoked, or expired).
- Verified through internal test requests that the corrected test page now serves a revoked certificate as required.
7. Preventive Measures
As of 2025-07-30, the following preventive measures have been finalized and implemented:
- Mandatory four-eyes review prior to test site certificate deployment to catch omissions or misconfigurations.
- Monitoring system that periodically scans test websites and flags any certificate status mismatches.
- Internal compliance audit checklist updated to include routine validation of test pages listed in CCADB.
- Version control and change logging mechanisms were reviewed and improved for test certificate deployment processes.
8. Impact
- Non-compliance with Baseline Requirements Section 2.2
- Potential misguidance of relying parties during revoked certificate handling tests
- Risk of undermining confidence in the reliability of test environments hosted by the CA
- Limited to test-only environment; no production certificates or relying parties were affected
9. Conclusion
NETLOCK acknowledges this non-conformity and has fully addressed the issue by investigating, remediating, verifying, and finalizing preventive controls. The CA remains committed to maintaining full compliance with CA/Browser Forum requirements and root store policies. No further action is pending regarding this incident.
Reporter: Chrome Root Program
Date of Observation: 2025-07-24
Date of Report: 2025-08-08
Reported by: NETLOCK Kft. – Compliance Team
Dear Community Members,
should you have any questions or comments regarding this ticket, we will be glad to provide clarification and respond accordingly.
Updated•1 year ago
|
Closure Summary
No questions or comments have been received regarding our report so far.
Incident description
This bug involved the NETLOCK test CA website serving an expired test certificate despite it being revoked, which violated policy expectations. The issue was identified following our report and was corrected.
Root cause analysis
Technical root cause
The expired certificate remained deployed on the test site due to an oversight in removal processes. Internal procedures did not ensure test environments were synchronized with revocation actions in a timely manner.
Organizational root cause
There were insufficient governance and monitoring controls to guarantee revocation enforcement across all environments, including staging and test. Responsibilities for synchronizing certificate removal were not clearly assigned.
Remediation actions
- removed the expired certificate from the NETLOCK test site to ensure only active certificates are served
- updated certificate publication protocols to include checks for expired or revoked certificates before deployment
- implemented monitoring that flags any test or staging environment serving expired certificates
Impact
- no expired or revoked certificates are currently being served
- test and staging environments now reflect the same certificate status as production
Final status of action items
| Action item | Kind | Status |
|---|---|---|
| remove expired certificate from test site | repair | completed |
| implement deployment checks for certificate validity | prevent | completed |
| establish monitoring for revoked/expired certificates in test envs | prevent | completed |
Lessons learned
- detection: checks now ensure expired or revoked certificates are caught before deployment
- governance: process clarity has improved for managing certificate deployments across environments
- preparedness: the organization is better equipped to avoid similar issues by enforcing environment parity and proactive monitoring
Commitment summary
NETLOCK regrets the oversight. Through enhancements in technical controls, operational processes, and governance, test environments are now aligned with revocation and certificate management standards. We request this bug be marked closed.
Comment 6•1 year ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-08-29.
Updated•1 year ago
|
Description
•