← Entrust cases
Bugzilla #1524876 Ca Certificate Compliance Certificate Misissuance

Entrust: IP address in dnsName (SAN dNSName)

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Entrust issuing TLS/SSL certificates with invalid dnsNames containing IP addresses in the SAN as a dNSName (sNSName). Jonathan Rudenberg notified Entrust on 2019-01-29 after identifying the issue, and Entrust opened this bug on 2019-02-03. Entrust stated that it modified its issuance policies in August 2016 to correct the dnsName discrepancy, but decided to allow existing certificates to expire rather than revoke, and later investigated and identified two certificates issued after the August 2016 patch. Entrust reported that investigation was complete, that subscribers were being contacted, and that the revocation process started, with a miss-issue report to be posted next. Entrust later provided a timeline and certificate list, and stated that all unexpired/unrevoked certificates were revoked on or before 2019-02-08 except four certificates scheduled for revocation on 2019-02-22. Entrust then granted a subscriber request to move the revocation date for the last four certificates to 2019-02-28, and those remaining four certificates were revoked on 2019-02-28. A Fastly participant commented that remediation appeared complete on 2019-03-01.

Model: gpt-5.4-nano Generated: 2026-06-13 18:01 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 10 comments
Chronology
  1. Entrust modified its issuance policies to correct the dnsName discrepancy but decided not to revoke existing certificates, allowing them to expire.
  2. Entrust was notified that certificates were issued with an IP address in the SAN as a dNSName.
  3. Bug 1524876 was opened to report the issue.
  4. Entrust revoked all unexpired/unrevoked certificates except four that were scheduled for later revocation.
  5. The four remaining certificates were originally scheduled to be revoked.
  6. The last four certificates were revoked after the revocation date was moved.
  7. A participant reported that remediation appeared complete.
Thread Activity
  1. Titanous representative — Opened the bug stating Entrust issued certificates with invalid dnsNames containing IP addresses and included links to affected certificates.
  2. Community commenter — Asked Bruce to provide an incident report because prior information in bug 1448986 appeared conflicting.
  3. Entrust representative — Explained Entrust’s August 2016 policy change and that a decision was made to let old certificates expire rather than revoke; stated investigation found two certificates miss-issued after the patch.
  4. Entrust representative — Referenced a CA/Browser Forum discussion and guidance on IP addresses in certificates.
  5. Community commenter — Confirmed the CA/Browser Forum guidance and noted the ballot did not proceed further because it was unnecessary.
  6. Entrust representative — Said investigation was complete, subscribers were being contacted, revocation had started, and a miss-issue report would be posted soon.
  7. Entrust representative — Provided a detailed response including timeline, confirmation that Entrust stopped issuing the problematic certificates in August 2016, and revocation steps and certificate lists.
  8. Entrust representative — Reported that Entrust granted a subscriber request to move the revocation date for the last four certificates to 2019-02-28.
  9. Entrust representative — Reported that the remaining four certificates were revoked on 2019-02-28.
  10. Fastly representative — Commented that it appears remediation is complete.
Participants
Titanous representative Community commenter Entrust representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1567659 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 94% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 94% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 88% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 87% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 87% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 87% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 86% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1667448 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 86% similar
Entrust: Incorrect keyUsage for ECC certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action