← Entrust cases
Bugzilla #1599484
Certificate Misissuance
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
RESOLVED
FIXED
Entrust
AI Summary
Entrust identified that 31 EV SSL certificates were incorrectly issued with the Business Category 'Non-Commercial Entity' instead of 'Private Organization'. The issue was discovered following a third-party notification on November 25, 2019. Entrust promptly initiated an internal review, confirmed the misissuance, and updated the affected customer profiles. All problematic certificates were revoked by November 29, 2019. Entrust has since revised its verification processes and implemented additional training to prevent future occurrences.
Chronology
- Notification received about potential misissuance of certificates.
- All 31 misissued certificates were revoked.
- Entrust completed verification process for Non-Commercial Entities allow list.
Participants
Dathan Demone
Ryan Sleevi
External References
Similar Local Cases
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
Entrust: Issued Certificates to incorrect Organization
Entrust: Certificate Issued with Incorrect Country Code
Entrust: Subscriber provides private key with CSR
Entrust: Question marks in certificate O and L fields
Entrust: Certificate issued with validity greater than 825-days
Entrust: Late mis-issue certificate revocation
Entrust: AffirmTrust Issuing CA Impacted by EJBCA Serial Number Issue