Entrust Datacard: Certificate issued with incorrect country code (AD instead of MM)
Entrust Datacard reported that it issued TLS/SSL certificates with an incorrect country code for an order involving embargoed or sanctioned countries. Entrust explained that its process approved an order and initiated a workflow to update the country code via an SQL script, but in this case the certificate was issued before the SQL script completed. Entrust said it noticed the invalid country code immediately before the script execution and then revoked the incorrect certificate and replaced it with a certificate containing the correct country code before the customer downloaded it. Entrust also investigated whether other certificates were impacted and performed scans; it reported finding one other mis-issued certificate where the country code was incorrect (C=GH used instead of C=LR). Entrust implemented a short-term process change requiring sanctioned-country order country codes to be updated before first-level approval, and it scheduled a long-term fix to eliminate the need for SQL scripts. Entrust later confirmed that the long-term fix went live on September 3, 2019, and that it would no longer use SQL scripts to update country codes for these orders. The Fastly reviewer responded that remediation was complete and no further questions remained.
- Entrust issued a certificate with an incorrect country code for a sanctioned/embargoed-country order, then revoked and replaced it after noticing the issue.
- Entrust reported implementing short-term controls and scheduling a long-term fix to remove SQL-script country-code updates.
- Entrust released the long-term fix eliminating SQL scripts for country-code updates on these orders.
- Entrustdatacard representative — Entrust described how a certificate was issued before an SQL script updated the country code, and provided a timeline including revocation and replacement of the incorrect certificate.
- Community commenter — Ryan requested timelines for short-term and long-term mitigations and asked for scan results regarding incorrect country codes, including concerns about SQL-script auditing.
- Entrustdatacard representative — Entrust stated the short-term process change was implemented, the long-term fix was scheduled for September 2019, and scans found one additional mis-issued certificate.
- Community commenter — Ryan indicated no further questions were expected pending review of the September timeline and emphasized auditing/control concerns.
- Fastly representative — Wthayer said there were no further questions and set the next update to 1-October.
- Entrustdatacard representative — Entrust confirmed the long-term fix went live on September 3 and that it would no longer use SQL scripts to update country codes for these orders.
- Fastly representative — Wthayer thanked Entrust and stated it appeared all questions were answered and remediation was complete.