Entrust: IP address in dnsName (SAN dNSName)
This case concerns Entrust issuing TLS/SSL certificates with invalid dnsNames containing IP addresses in the SAN as a dNSName (sNSName). Jonathan Rudenberg notified Entrust on 2019-01-29 after identifying the issue, and Entrust opened this bug on 2019-02-03. Entrust stated that it modified its issuance policies in August 2016 to correct the dnsName discrepancy, but decided to allow existing certificates to expire rather than revoke, and later investigated and identified two certificates issued after the August 2016 patch. Entrust reported that investigation was complete, that subscribers were being contacted, and that the revocation process started, with a miss-issue report to be posted next. Entrust later provided a timeline and certificate list, and stated that all unexpired/unrevoked certificates were revoked on or before 2019-02-08 except four certificates scheduled for revocation on 2019-02-22. Entrust then granted a subscriber request to move the revocation date for the last four certificates to 2019-02-28, and those remaining four certificates were revoked on 2019-02-28. A Fastly participant commented that remediation appeared complete on 2019-03-01.
- Entrust modified its issuance policies to correct the dnsName discrepancy but decided not to revoke existing certificates, allowing them to expire.
- Entrust was notified that certificates were issued with an IP address in the SAN as a dNSName.
- Bug 1524876 was opened to report the issue.
- Entrust revoked all unexpired/unrevoked certificates except four that were scheduled for later revocation.
- The four remaining certificates were originally scheduled to be revoked.
- The last four certificates were revoked after the revocation date was moved.
- A participant reported that remediation appeared complete.
- Titanous representative — Opened the bug stating Entrust issued certificates with invalid dnsNames containing IP addresses and included links to affected certificates.
- Community commenter — Asked Bruce to provide an incident report because prior information in bug 1448986 appeared conflicting.
- Entrust representative — Explained Entrust’s August 2016 policy change and that a decision was made to let old certificates expire rather than revoke; stated investigation found two certificates miss-issued after the patch.
- Entrust representative — Referenced a CA/Browser Forum discussion and guidance on IP addresses in certificates.
- Community commenter — Confirmed the CA/Browser Forum guidance and noted the ballot did not proceed further because it was unnecessary.
- Entrust representative — Said investigation was complete, subscribers were being contacted, revocation had started, and a miss-issue report would be posted soon.
- Entrust representative — Provided a detailed response including timeline, confirmation that Entrust stopped issuing the problematic certificates in August 2016, and revocation steps and certificate lists.
- Entrust representative — Reported that Entrust granted a subscriber request to move the revocation date for the last four certificates to 2019-02-28.
- Entrust representative — Reported that the remaining four certificates were revoked on 2019-02-28.
- Fastly representative — Commented that it appears remediation is complete.