Open
Bug 2075720
Opened 7 hours ago
NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
UNCONFIRMED
People
(Reporter: kaluha.roland, Unassigned)
Details
Preliminary Incident Report
Summary
-
Incident description:
A third party reported that the CRL of the root CA NetLock Arany (Class Gold) Főtanúsítvány, published at https://crl1.netlock.hu/index.cgi?crl=gold, was served in two different versions under the same cRLNumber (39):- Until 2026-09-25, the URL served a CRL with cRLNumber 39, thisUpdate 2025-12-18T14:14:09Z and 13 entries.
- Later on 2026-09-25, the URL served a different CRL, also with cRLNumber 39 and the same thisUpdate and nextUpdate, containing two additional entries: 49412CE4001F and 49412CE40021 (revocation date 2018-08-16).
According to the reporter, both CRLs carry the same issuer name and authorityKeyIdentifier, and both signatures verify against the NetLock Arany (Class Gold) Főtanúsítvány key. A reissued CRL with changed contents should carry a higher cRLNumber and a thisUpdate reflecting its actual issuance time. NETLOCK has received the report and is investigating. A full incident report will follow.
-
Relevant policies:
- RFC 5280 §5.2.3 requirements for the cRLNumber extension (monotonically increasing sequence for a given CRL scope).
- RFC 5280 §5.1.2.4 definition of the thisUpdate field (issue date of the CRL).
- CA/Browser Forum Baseline Requirements §7.2.2 requirements for the CRL Number (strictly increasing).
- CCADB incident reporting guidelines requiring disclosure of any non-compliance affecting CA certificates.
-
Source of incident disclosure:
Third Party Reported.
You need to log in
before you can comment on or make changes to this bug.
Description
•