← Entrust cases
Bugzilla #1448986 Self Reported Incident

Entrust: IP Address in dNSName form

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust Datacard identified an issue with SSL certificates that incorrectly listed an IP address in the dNSName field instead of the iPAddress field. The problem was first noticed on March 22, 2018, leading to an investigation and the revocation of the affected certificates on March 23, 2018. Entrust implemented a bug fix on March 26, 2018, to prevent future occurrences. They have since committed to enhancing their compliance checks, including plans for pre-issuance linting to further ensure certificate validity. The issue has been resolved, and no further certificates were issued with this problem during the investigation period.

Model: gpt-4o-mini Generated: 2026-06-13 17:46 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.90 21 comments
Chronology
  1. Entrust became aware of an invalidly-formed certificate.
  2. Entrust revoked the invalidly formed certificates.
  3. Entrust implemented a bug fix.
  4. Entrust implemented pre-issuance linting for all public trust SSL certificates.
Thread Activity
  1. Entrust representative — Entrust issued an SSL certificate with an IP Address incorrectly indicated in the dNSName form.
  2. Community commenter — Questioned Entrust's monitoring of external resources for misissuance events.
  3. Entrust representative — Entrust plans to implement hourly post-issuance checks for all certificate types.
  4. Entrust representative — Confirmed plans to implement pre-issuance linting.
  5. Entrust representative — Pre-issuance linting for all public trust SSL certificates has been implemented.
Participants
Entrust representative Community commenter Fastly representative
External References
Similar Local Cases
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 100% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 95% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1897630 RESOLVED Self Reported Incident Opened 2024-05-19 · Closed 2024-08-15 · 92% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1390996 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 91% similar
Entrust: Non-BR-Compliant Certificate Issuance
#1952635 RESOLVED Self Reported Incident Opened 2025-03-08 · Closed 2025-08-11 · 90% similar
Entrust: Missing or Inconsistent Disclosure of S/MIME BR Audits
#1658792 RESOLVED Self Reported Incident Opened 2020-08-12 · Closed 2023-02-22 · 89% similar
Entrust: Invalid data in State/Province Field
#1879602 RESOLVED Security Incident Self Reported Incident Opened 2024-02-09 · Closed 2024-07-19 · 88% similar
Entrust: OCSP response signed with SHA-1
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 87% similar
Entrust: Certificate issued with validity greater than 825-days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action