← Entrust cases
Bugzilla #1268225 Ca Certificate Compliance

Entrust: Invalid TeletexString / T61String in certificate DirectoryString fields

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that some Entrust-issued certificates contain invalid TeletexString/T61String values in DirectoryString fields. The reporter provided an example certificate on crt.sh and explained that the organizationName contains hex bytes that should likely represent “Väestörekisterikeskus” but are not valid under the relevant X.690/X.680 character set assumptions. The reporter also argued that the CA appears to use an incorrect character mapping and that the CA should follow RFC 5280 guidance on DirectoryString encodings. Entrust acknowledged the bug, stated it had a fix, and said it was testing before deployment. Entrust later reported that the fix had been implemented and that the issue was no longer indicated by cablint after about a week. The bug was then closed as fixed at the reporter’s request.

Model: gpt-5.4-nano Generated: 2026-06-13 14:03 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.86 6 comments
Chronology
  1. Bug opened reporting invalid TeletexString/T61String encodings in Entrust certificate fields.
  2. Entrust began testing a fix for the invalid string encoding issue.
  3. Entrust reported the fix was deployed and the issue no longer appeared in cablint results.
Thread Activity
  1. Roeckx representative — Reported that various certificates have invalid TeletexString/T61String values (example on crt.sh) and argued the encoding/character mapping is incorrect per X.690/X.680 and RFC 5280.
  2. Mozilla representative — Asked Entrust to resolve the issues listed and update the bug with progress.
  3. Entrust representative — Confirmed Entrust is aware, has a fix, and is currently testing, with an update after deployment.
  4. Entrust representative — Reported the fix was implemented and that the issue is no longer indicated by cablint after about a week.
  5. Mozilla representative — Requested closing the bug as fixed.
  6. Roeckx representative — Agreed to close as fixed.
Participants
Roeckx representative Entrust representative Mozilla representative
Similar Local Cases
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 68% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 68% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 67% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#611283 RESOLVED Ca Certificate Compliance Opened 2010-11-11 · Closed 2022-11-14 · 67% similar
StartCom cert not working in Firefox 4 beta
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 67% similar
Entrust: EV TLS Certificate incorrect jurisdiction
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 66% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1521520 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-21 · Closed 2023-02-22 · 66% similar
Entrust: Late revocation of underscore certificate
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 65% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action