Entrust: Non-BR-Compliant Certificate Issuance
Entrust disclosed a compliance issue regarding the issuance of TLS/SSL certificates that contained non-compliant metadata, specifically a hyphen in the organizational unit (OU) field. The CA first became aware of the issue through a forum discussion on August 9, 2017, and confirmed that it had ceased issuing such certificates. Entrust identified five certificates with the problematic metadata, two of which had already expired, while the remaining three were set to expire soon. The CA decided not to revoke the unexpired certificates, citing no security risks. Entrust has since implemented enhanced education and software checks to prevent future occurrences. The issue was marked as resolved after the necessary changes were completed.
- Entrust became aware of compliance issues through a forum discussion.
- Entrust completed deployment of software fail-safe checks to prevent issuance of non-compliant certificates.
- Mozilla representative — Reported compliance issues with certificates issued by Entrust.
- Entrustdatacard representative — Confirmed that Entrust has stopped issuing non-compliant certificates.
- Entrustdatacard representative — Stated that no security issues were found with the previously issued certificates.
- Entrustdatacard representative — Announced completion of software fail-safe checks for OU values.