← Entrust cases
Bugzilla #1521520
Certificate Problem Report
Entrust: Late revocation of underscore certificate
RESOLVED
FIXED
Entrust
AI Summary
Entrust failed to revoke nine SSL certificates containing underscores before the January 15, 2019 deadline set by the CA/Browser Forum. Although Entrust had encouraged subscribers to revoke such certificates, a flawed SQL query led to the oversight. The issue was detected after notification from Netcraft, prompting an investigation that revealed the missed revocations. Entrust has since updated their processes to prevent similar issues in the future, including changes to their query and requiring additional reviews for compliance activities.
Chronology
- Notification received that not all underscore certificates were revoked.
- Investigation completed to determine which certificates were not revoked.
- Cause for error identified and all certificates revoked.
- Discussion on using Certificate Transparency for future verification.
Participants
Bruce Morton
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: IP Address in dNSName form
Entrust: Printable String Constraint Failure
Entrust: Certificate issued with '-' in ST field
Entrust: Failure to revoke a certificate
Entrust: Incorrect keyUsage for ECC certificate
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Entrust: SSL Certificates issued with Un-verified IP Addresses