← Entrust cases
Bugzilla #1627346
Certificate Problem Report
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
RESOLVED
FIXED
Entrust
AI Summary
Entrust issued six S/MIME certificates in May 2019 with an incorrect certificate policy OID. The issue was discovered on March 31, 2020, during a compliance audit, and the certificates were subsequently revoked on April 2, 2020. Entrust has confirmed that no other misissuances of this nature have gone unreported and has updated its internal processes to prevent future occurrences. The incorrect OID was initially implemented in the QA test system and was not detected until after production deployment.
Chronology
- Six S/MIME certificates issued with incorrect certificate policy OID.
- Issue discovered during compliance audit.
- All six certificates revoked.
- Internal CPR process updated.
Participants
Bruce Morton
Wayne Thayer
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
Entrust: Printable String Constraint Failure
Entrust: SSL Certificates issued with Un-verified IP Addresses
Entrust: Failure to revoke a certificate
Entrust: IP Address in dNSName form
Entrust: Late revocation of underscore certificate
Entrust: Incorrect keyUsage for ECC certificate
Entrust: Certificate issued with '-' in ST field
Entrust: EV Certificate missing Issuer’s EV Policy OID