Entrust: Late revocation of underscore certificates (SC13 deadline)
This case reports that Entrust Datacard did not revoke all SSL/TLS certificates containing underscore characters by the CA/Browser Forum ballot SC13 deadline of 15 January 2019. Entrust stated that it received notice from Netcraft that some of its certificates were not revoked, and that a search for unexpired/unrevoked underscore certificates failed to find all relevant certificates. Entrust provided a timeline indicating it notified stakeholders on 18 January 2019, completed investigation the same day, determined the cause, and revoked all certificates by 18 January 2019 18:53 UTC. Entrust said the underlying issue was a flawed SQL query used to find unrevoked certificates, which missed certificates in “reissued” and “renewed” states and also certificates scheduled for delayed revocation. Entrust also stated it had stopped issuing TLS/SSL certificates with underscores on 7 December 2018. The bug was resolved as FIXED, with Entrust reporting that the SQL query was updated to prevent the search error from recurring and that future report queries would be reviewed by at least one other person for correctness.
- SC13 deadline passed without revocation of all underscore-containing SSL/TLS certificates.
- Entrust investigated and then revoked the remaining underscore-containing certificates after identifying the issue.
- Entrust stopped issuing TLS/SSL certificates with underscores.
- Entrust representative — Reported that Entrust did not revoke all underscore SSL certificates issued more than 30 days before the 15 January 2019 deadline and described the investigation timeline and remediation steps.
- Fastly representative — Asked how the problem was detected, why some certificates were revoked before detection, and what process changes would prevent recurrence.
- Entrust representative — Said Netcraft notified Entrust of the issue, explained that some certificates were revoked earlier due to subscriber replacement with delayed revocation, and stated the search query was updated to avoid recurrence.
- Community commenter — Requested more systemic root-cause and prevention details rather than only what was changed.
- Entrust representative — Clarified that the search query was incorrect, that it was corrected immediately, and that the query was updated for future use.
- Community commenter — Continued to note that the thread did not yet demonstrate systemic prevention and asked for further explanation.
- Entrust representative — Provided details on the missed certificate states (“reissued” and “renewed”), described the query fix (ignoring certificate state and looking only at revocation state), and stated a process change requiring an additional reviewer for future compliance report queries.
- Community commenter — Suggested cross-checking internal query results against public data sources like Certificate Transparency and asked whether Entrust would incorporate such a process.
- Entrust representative — Said they discussed using CT in retrospect and that they may ask Netcraft to do an external check in the future.