Entrust self-reported S/MIME certificates with incorrect policy OID and delayed revocation
Entrust reported that six S/MIME certificates were issued in May 2019 with the wrong certificate policy OID. The issue was first discovered internally on 2020-03-31 during Deloitte’s annual compliance audit, and Entrust said the certificates had not been revoked at that time. Entrust explained that the incorrect OID had been introduced in the QA test system, carried into production, and detected by post-issuance linting. Entrust later stated that all six certificates were revoked on 2020-04-01 and 2020-04-02, and that it had updated its internal CPR process to mirror its external process. Mozilla participants asked for clarification about whether any similar issues had gone undisclosed and whether the remediation also addressed prevention of future misissuance.
- Six S/MIME certificates were issued with an incorrect certificate policy OID.
- The incorrect certificate policy OID was corrected in the system.
- Entrust discovered the six misissued certificates during its annual compliance audit.
- Entrust revoked two of the misissued certificates.
- Entrust revoked the remaining four misissued certificates.
- Entrust said its internal CPR process had been updated.
- Entrust representative — Entrust opened the bug and said six S/MIME certificates were issued with the incorrect certificate policy OID.
- Entrust representative — Entrust said it discovered the issue on 2020-03-31, that the certificates were not initially revoked, and that all six were later revoked.
- Fastly representative — Wayne Thayer asked whether any other similar misissuances had gone unreported and asked what would prevent future misissuance.
- Entrust representative — Entrust said no other misissuances of this nature had gone unreported and explained the QA-to-production templating mistake.
- Community commenter — Ryan Sleevi asked whether any other system configuration errors had been placed into production but not reported as CA incidents.
- Entrust representative — Entrust said there had been no other non-disclosed system configuration errors placed into production and said the issue would be publicly disclosed through Bugzilla.
- Fastly representative — Wayne Thayer asked Entrust to update the bug when the internal CPR process update was complete.
- Entrust representative — Entrust said the internal CPR process had been updated.
- Mozilla representative — Ben Wilson asked for clarification about the updated internal documentation and the CPR process wording.
- Entrust representative — Entrust confirmed that internal documentation had been updated and explained the CPR information source it was referring to.