← Entrust cases
Bugzilla #1428891 Delayed Revocation

Entrust: Non-BR-Compliant OCSP Responder

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Entrust OCSP responders for the Entrust Class 1 Client CA and Entrust Class 2 Client CA intermediates returning a “good” response for an invalid serial number, which Wayne Thayer reported as non-compliant with the Baseline Requirements. Thayer cited BR section 4.9.10, stating OCSP responders must not respond with “good” for unissued certificates (effective 2013-08-01), and asked Entrust to provide an incident report or revoke non-constrained certificates. Entrust said it became aware of the problem via the Bugzilla report email and provided a response plan, stating it would update the OCSP responders to only return “good” for known, non-revoked serial numbers. Entrust also stated that it was not issuing TLS/SSL certificates with the problem and that there were no problematic certificates issued, while later clarifying that the Class 1 and Class 2 CAs had issued S/MIME certificates pointing to these responders (and 0 TLS/SSL certificates). Entrust reported that the OCSP system was corrected on 2018-01-25. Mozilla confirmed the OCSP responders were no longer reported as non-compliant by crt.sh and the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:42 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.50 8 comments
Chronology
  1. Wayne Thayer reported that Entrust OCSP responders returned “good” for invalid serial numbers, citing BR 4.9.10.
  2. Entrust corrected the OCSP system so it would no longer return “good” for invalid/unissued serial numbers.
  3. Mozilla/Wayne confirmed the OCSP responders were no longer reported as non-compliant and the bug was resolved.
Thread Activity
  1. Fastly representative — Reported that Entrust OCSP responders returned “good” for an invalid serial number and requested an incident report or remediation per BR 4.9.10.
  2. Entrust representative — Described how Entrust learned of the issue and stated it planned to update OCSP responders to only return “good” for known, non-revoked serial numbers.
  3. Mozilla representative — Suggested that unconstrained certs either need disclosure/audit as SSL intermediates or be added to OneCRL as an option for legacy certificates.
  4. Entrust representative — Stated the CAs are disclosed in CCADB, annually audited to WebTrust for CA, and configured not to issue SSL certificates.
  5. Community commenter — Asked for clarification on whether certificates point to the OCSP responders and noted the effect of OCSP non-compliance on issued certificates.
  6. Entrust representative — Clarified that Class 1 and Class 2 CAs issued S/MIME certificates pointing to the responders (23259 from 2016-02-01 to 2017-11-30) and 0 TLS/SSL certificates.
  7. Entrust representative — Reported that the OCSP system was corrected.
  8. Fastly representative — Confirmed crt.sh no longer reported the OCSP responders as non-compliant and resolved the bug.
Participants
Fastly representative Entrust representative Mozilla representative Community commenter
Similar Local Cases
#1521520 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-21 · Closed 2023-02-22 · 68% similar
Entrust: Late revocation of underscore certificate
#1636339 RESOLVED Delayed Revocation Opened 2020-05-08 · Closed 2023-02-22 · 64% similar
Entrust: Failure to revoke a certificate
#1520876 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-17 · Closed 2023-02-22 · 61% similar
Entrust: Late mis-issue certificate revocation
#1943528 RESOLVED Delayed Revocation Opened 2025-01-24 · Closed 2025-02-19 · 55% similar
Entrust: delayed revocation
#1885754 RESOLVED Delayed Revocation Opened 2024-03-16 · Closed 2024-09-13 · 54% similar
Entrust: CPR was not responded to in 24 hours
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 53% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1910237 RESOLVED Delayed Revocation Closure Request Opened 2024-07-27 · Closed 2025-05-13 · 53% similar
Entrust: Delayed Revocation for S/MIME certificates
#1931886 RESOLVED Revocation Issue Opened 2024-11-18 · Closed 2025-02-12 · 53% similar
Entrust: CRL missing revocation reasonCode

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action