Entrust: Late mis-issue certificate revocation
This case concerns Entrust Datacard revoking a mis-issued certificate after the 5-day deadline. Entrust stated that the deadline was not defined properly, and that the mis-issued certificate was revoked on November 26, 2018, after the investigation and response timeline described in the thread. Entrust said it became aware of the problem when it revoked the certificate after the deadline and noticed the issue while documenting the revoked certificate’s mis-issuance report. Entrust reported that it updated its process to define a starting time and a revocation deadline, and that it stopped issuing TLS/SSL certificates with the problem. Entrust also described remediation steps including setting a 24-hour alarm in its support system with a notice to a distribution list to ensure revocation occurs before the deadline. A later comment indicated that remediation was complete, and the bug is resolved as FIXED.
- A certificate was issued.
- The mis-issuance was detected and an investigation started.
- The mis-issued certificate was revoked after the 5-day deadline.
- Entrust changed its process during the investigation period.
- Entrust representative — Reported that a mis-issued certificate was not revoked within the 5-day deadline because the deadline was not defined properly.
- Entrust representative — Provided details on how Entrust became aware, a UTC timeline, confirmation that TLS/SSL issuance was stopped with the problematic process, and remediation steps including setting a 24-hour alarm and defining the revocation deadline based on notification time.
- Community commenter — Asked whether Entrust’s proposed deadline approach is compatible with Baseline Requirements, noting notification may occur after the CA is made aware.
- Entrust representative — Responded that BR 4.9.1.1 allows the 5-day period to start as late as the time the CA obtains evidence of certificate misuse.
- Fastly representative — Commented that it appears remediation is complete.