Entrust: IP Address in dNSName form
Entrust Datacard identified an issue with SSL certificates that incorrectly listed an IP address in the dNSName field instead of the iPAddress field. The problem was first noticed on March 22, 2018, leading to an investigation and the revocation of the affected certificates on March 23, 2018. Entrust implemented a bug fix on March 26, 2018, to prevent future occurrences. They have since committed to enhancing their compliance checks, including plans for pre-issuance linting to further ensure certificate validity. The issue has been resolved, and no further certificates were issued with this problem during the investigation period.
- Entrust became aware of an invalidly-formed certificate.
- Entrust revoked the invalidly formed certificates.
- Entrust implemented a bug fix.
- Entrust implemented pre-issuance linting for all public trust SSL certificates.
- Entrust representative — Entrust issued an SSL certificate with an IP Address incorrectly indicated in the dNSName form.
- Community commenter — Questioned Entrust's monitoring of external resources for misissuance events.
- Entrust representative — Entrust plans to implement hourly post-issuance checks for all certificate types.
- Entrust representative — Confirmed plans to implement pre-issuance linting.
- Entrust representative — Pre-issuance linting for all public trust SSL certificates has been implemented.