← Entrust cases
Bugzilla #1561013 Self Reported Incident Certificate Misissuance

Entrust: Certificate issued with validity greater than 825-days

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust Datacard discovered a compliance issue involving the issuance of certificates with a validity period exceeding 825 days during internal testing on June 21, 2019. Upon discovery, the CA revoked the two affected certificates within hours. Further investigation revealed a total of five certificates were mis-issued due to manual errors in the issuance process. Entrust has since implemented a new procedure to prevent future occurrences and has ceased issuing certificates with incorrect validity periods. The issue has been resolved, and the CA has completed the necessary remediation steps.

Model: gpt-4o-mini Generated: 2026-06-13 18:15 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.85 19 comments
Chronology
  1. Entrust issued two certificates with a validity period greater than 825 days.
  2. Entrust discovered the issue and revoked the certificates.
  3. Entrust completed the deployment of the new procedures to prevent future mis-issuances.
Thread Activity
  1. Entrust representative — Entrust reported the issuance of an EV SSL certificate for 3 years, exceeding the allowed validity period.
  2. Entrust representative — Entrust updated the report to indicate five certificates were mis-issued due to the same root cause.
  3. Entrust representative — Entrust confirmed that the release accommodating the new procedures has been deployed.
Participants
Community commenter
External References
Similar Local Cases
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 100% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1673119 RESOLVED Self Reported Incident Opened 2020-10-23 · Closed 2023-02-22 · 100% similar
Entrust: Subscriber provides private key with CSR
#1512018 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-12-04 · Closed 2023-02-22 · 99% similar
Entrust: Certificate issued with '-' in ST field
#1635096 RESOLVED Self Reported Incident Opened 2020-05-04 · Closed 2023-02-22 · 99% similar
Entrust: Printable String Constraint Failure
#1535735 RESOLVED Certificate Misissuance Opened 2019-03-15 · Closed 2023-02-22 · 97% similar
Entrust: Issued Certificates to incorrect Organization
#1648472 RESOLVED Self Reported Incident Opened 2020-06-25 · Closed 2024-06-30 · 97% similar
Entrust: SHA-256 hash algorithm used with ECC P-384 key
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 92% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1696227 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2021-03-03 · Closed 2023-02-22 · 91% similar
Entrust: Incorrect Jurisdiction Country Value in an EV Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action