Entrust: SHA-1 issuance and other misissuance while testing (incident report)
This case reports that Entrust issued four certificates with problems while testing a procedure to remediate a prior incident. Entrust stated that, during finalizing of the Phase 1 procedure, four certificates were miss-issued due to manual error. One certificate was issued with the incorrect profile and was signed using SHA-1, had no subjectAltName, and was missing the HTTP URL for the CDP; Entrust provided a crt.sh link for it. Three other certificates were issued to the correct profile but contained a spelling error in the OCSP response URL; Entrust provided crt.sh links for those certificates. Entrust said the problematic certificates were revoked or had expired, and that it stopped issuing certificates using the incorrect policy and with spelling errors. Entrust also described remediation steps, including limiting manual issuance and moving toward a more automated issuance solution supported by a policy engine and pre-issuance linting, with new certificates to be reissued as recovery where possible. In the thread, Entrust later confirmed that manual issuance is approved under dual custody and provided details of its “hand-roll” process and review/linting steps. The reporter stated that remediation was complete.
- Entrust manually issued certificates while testing a remediation procedure, including one SHA-1-signed EV certificate with missing SAN/HTTP CDP URL and three certificates with an OCSP URL spelling error.
- Entrust discovered the OCSP URL spelling error and revoked one of the affected certificates.
- Entrust reported the misissuances and requested an incident report per Mozilla’s incident-reporting guidance.
- Entrust provided a detailed incident report timeline and remediation plan in response to Mozilla’s questions.
- The reporter indicated that remediation was complete.
- Fastly representative — Wayne Thayer relayed Entrust’s report that four certificates were miss-issued due to manual error during Phase 1 procedure finalization, including one SHA-1-signed certificate with missing SAN and HTTP CDP URL and three certificates with an OCSP URL spelling error, and noted the certificates were revoked or expired while requesting an incident report.
- Entrust representative — Bruce Morton provided answers to the requested incident-report questions, including how Entrust discovered the issues during testing, a timestamped timeline, the certificate problems, and steps to resolve and prevent recurrence (limiting manual issuance and moving to automated issuance with policy engine and pre-issuance linting).
- Community commenter — Ryan Sleevi asked for more detail about Entrust’s controls around manual issuance and the process timeline leading up to the July 4 issuance events.
- Entrust representative — Bruce Morton described Entrust’s manual issuance context and stated that the errors were manual errors (incorrect profile selection and a typo in the certificate profile) and that the CA has stopped using incorrect policy/profile combinations.
- Community commenter — Ryan Sleevi expressed concern that the incident understanding and mitigation were not sufficiently demonstrated and requested additional historical process detail and the post-incident changes.
- Entrust representative — Bruce Morton provided a detailed “hand-roll” process with dual custody/review steps, explained where the failures occurred (profile selection and a typo in the certificate specification), and described the move to API-based issuance with pre-validated data, policy-engine checks, pre-issuance linting, and CT logging.
- Entrust representative — Bruce Morton said he would have a response after working with the development team and noted he would be on leave until 12 August 2019.
- Entrust representative — Bruce Morton responded that there is minimal possibility for an employee to select an incorrect profile due to manual issuance being rare and requiring approval under dual custody, and described QA review and linting practices and increased monitoring plans.
- Fastly representative — Wayne Thayer stated that it appears all questions have been answered and remediation is complete.