← Entrust cases
Bugzilla #1448986
Certificate Problem Report
Entrust: IP Address in dNSName form
RESOLVED
FIXED
Entrust
AI Summary
Entrust identified an issue with SSL certificates that incorrectly logged IP addresses in the dNSName format instead of the iPAddress format. The problem was first reported on March 22, 2018, leading to a swift investigation and the revocation of the affected certificates. A bug fix was implemented by March 26, 2018, ensuring that no further certificates were issued with this issue. Entrust has since enhanced its compliance checks and plans to implement pre-issuance linting to prevent similar issues in the future.
Chronology
- Received incident notice regarding invalidly-formed certificate.
- Started investigation and testing for other certificates.
- Implemented bug fix and revoked invalidly formed certificates.
- Pre-issuance linting for all public trust SSL certificates implemented.
Participants
Bruce Morton
Ryan Sleevi
Wayne Thayer
External References
Similar Local Cases
Entrust: Printable String Constraint Failure
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: Late revocation of underscore certificate
Entrust: SSL Certificates issued with Un-verified IP Addresses
Entrust: Incorrect keyUsage for ECC certificate
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Entrust: Failure to revoke a certificate
Entrust: Certificate issued with '-' in ST field