← Entrust cases
Bugzilla #1535735
Certificate Misissuance
Entrust: Issued Certificates to incorrect Organization
RESOLVED
FIXED
Entrust
AI Summary
Entrust Datacard issued OV SSL certificates with incorrect organization names due to a human error in updating account information. The issue was identified on March 7, 2019, after 48 certificates had been issued with the wrong organization name. Entrust promptly corrected the error and initiated a revocation process for the affected certificates, which was completed by March 20, 2019. The incident highlighted the need for improved procedures to prevent similar occurrences in the future.
Chronology
- Customer requested to change contact information, leading to incorrect organization name update.
- Entrust noticed the discrepancy during a routine account lookup.
- Error confirmed and corrective actions initiated.
- All affected certificates successfully revoked.
Participants
Bruce Morton
Dathan Demone
Ryan Sleevi
External References
Similar Local Cases
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
Entrust: Subscriber provides private key with CSR
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
Entrust: Certificate issued with validity greater than 825-days
Entrust: Certificate Issued with Incorrect Country Code
Entrust: Late mis-issue certificate revocation
Entrust: SHA-1 Issuance and other misissuance while testing
Entrust: SHA-256 hash algorithm used with ECC P-384 key