Entrust: Invalid TeletexString / T61String in certificate DirectoryString fields
This case reports that some Entrust-issued certificates contain invalid TeletexString/T61String values in DirectoryString fields. The reporter provided an example certificate on crt.sh and explained that the organizationName contains hex bytes that should likely represent “Väestörekisterikeskus” but are not valid under the relevant X.690/X.680 character set assumptions. The reporter also argued that the CA appears to use an incorrect character mapping and that the CA should follow RFC 5280 guidance on DirectoryString encodings. Entrust acknowledged the bug, stated it had a fix, and said it was testing before deployment. Entrust later reported that the fix had been implemented and that the issue was no longer indicated by cablint after about a week. The bug was then closed as fixed at the reporter’s request.
- Bug opened reporting invalid TeletexString/T61String encodings in Entrust certificate fields.
- Entrust began testing a fix for the invalid string encoding issue.
- Entrust reported the fix was deployed and the issue no longer appeared in cablint results.
- Roeckx representative — Reported that various certificates have invalid TeletexString/T61String values (example on crt.sh) and argued the encoding/character mapping is incorrect per X.690/X.680 and RFC 5280.
- Mozilla representative — Asked Entrust to resolve the issues listed and update the bug with progress.
- Entrust representative — Confirmed Entrust is aware, has a fix, and is currently testing, with an update after deployment.
- Entrust representative — Reported the fix was implemented and that the issue is no longer indicated by cablint after about a week.
- Mozilla representative — Requested closing the bug as fixed.
- Roeckx representative — Agreed to close as fixed.