← Entrust cases
Bugzilla #1567659
Certificate Misissuance
Entrust: SHA-1 Issuance and other misissuance while testing
RESOLVED
FIXED
Entrust
AI Summary
Entrust reported multiple misissuances of certificates during testing, including one certificate signed with SHA-1 and lacking a subjectAltName, as well as three certificates with incorrect OCSP URLs. All affected certificates have since been revoked or expired. The issues arose from manual errors during the issuance process, which Entrust has since addressed by implementing stricter controls and moving towards automated issuance solutions to prevent future occurrences.
Chronology
- Manual issuance of an EV SSL certificate using the wrong profile.
- Discovery of spelling errors in OCSP URLs for three certificates.
- Entrust provided detailed incident report and timeline of events.
- Confirmation that all questions have been answered and remediation is complete.
Participants
Wayne Thayer
Bruce Morton
Ryan Sleevi
External References
Similar Local Cases
Entrust: Certificate issued with validity greater than 825-days
Entrust: Question marks in certificate O and L fields
Entrust: Subscriber provides private key with CSR
Entrust: Issued Certificates to incorrect Organization
Entrust: SHA-256 hash algorithm used with ECC P-384 key
Entrust: Late mis-issue certificate revocation
Entrust: IP in dnsName
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate