← Entrust cases
Bugzilla #1390996
Policy Compliance
Entrust: Non-BR-Compliant Certificate Issuance
RESOLVED
FIXED
Entrust
AI Summary
Entrust faced issues with the issuance of TLS/SSL certificates that did not comply with Baseline Requirements (BRs), specifically concerning metadata-only subject fields. The CA acknowledged the problems and confirmed that they ceased issuing non-compliant certificates. They provided a list of affected certificates and outlined steps taken to prevent future occurrences, including enhanced education for their verification team and software changes to block problematic values. The issue was resolved with the implementation of fail-safe checks in November 2017.
Chronology
- Initial report of non-compliance issues.
- Entrust confirmed awareness of the issues and stopped issuing non-compliant certificates.
- Deployment of software fail-safe checks completed.
Participants
Kathleen Wilson
Kirk Hall
Jonathan Rudenberg
Stephen Hillier
Ryan Sleevi
External References
Similar Local Cases
Actalis: Non-BR-Compliant Certificate Issuance
Izenpe: Non-BR-Compliant Certificate Issuance
Kamu SM: Non-BR-Compliant Certificate Issuance
QuoVadis: Non-BR-Compliant Certificate Issuance
GoDaddy: Non-BR-Compliant Certificate Issuance
certSIGN: Non-BR-Compliant Certificate Issuance
SwissSign: Non-BR-Compliant Certificate Issuance
SECOM: Non-BR-Compliant Certificate Issuance