Open Bug 2075720 Opened 7 hours ago

NETLOCK Certificate Problem Report [CRL RFC 5280 S5.2.3]

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: kaluha.roland, Unassigned)

Details

Preliminary Incident Report

Summary

  • Incident description:
    A third party reported that the CRL of the root CA NetLock Arany (Class Gold) Főtanúsítvány, published at https://crl1.netlock.hu/index.cgi?crl=gold, was served in two different versions under the same cRLNumber (39):

    • Until 2026-09-25, the URL served a CRL with cRLNumber 39, thisUpdate 2025-12-18T14:14:09Z and 13 entries.
    • Later on 2026-09-25, the URL served a different CRL, also with cRLNumber 39 and the same thisUpdate and nextUpdate, containing two additional entries: 49412CE4001F and 49412CE40021 (revocation date 2018-08-16).

    According to the reporter, both CRLs carry the same issuer name and authorityKeyIdentifier, and both signatures verify against the NetLock Arany (Class Gold) Főtanúsítvány key. A reissued CRL with changed contents should carry a higher cRLNumber and a thisUpdate reflecting its actual issuance time. NETLOCK has received the report and is investigating. A full incident report will follow.

  • Relevant policies:

    • RFC 5280 §5.2.3 requirements for the cRLNumber extension (monotonically increasing sequence for a given CRL scope).
    • RFC 5280 §5.1.2.4 definition of the thisUpdate field (issue date of the CRL).
    • CA/Browser Forum Baseline Requirements §7.2.2 requirements for the CRL Number (strictly increasing).
    • CCADB incident reporting guidelines requiring disclosure of any non-compliance affecting CA certificates.
  • Source of incident disclosure:
    Third Party Reported.

You need to log in before you can comment on or make changes to this bug.