← Entrust cases
Bugzilla #1635096
Certificate Problem Report
Entrust: Printable String Constraint Failure
RESOLVED
FIXED
Entrust
AI Summary
Entrust Datacard identified a compliance issue where an SSL certificate was issued with quotation marks in the printable string format of the Organization field in the Subject DN. This error was discovered during a routine audit on April 30, 2020, leading to the revocation of the certificate on May 1, 2020. The CA's software had a bug that allowed this misissuance, which was not detected during pre-issuance checks. Entrust is working on migrating to updated software to prevent future occurrences and has implemented a patch to address the OCSP response issue.
Chronology
- SSL certificate issued with invalid characters.
- Certificate revoked on CRL.
- OCSP system patched and certificate revoked on OCSP.
Participants
Bruce Morton
Wayne Thayer
Ryan Sleevi
Ben Wilson
External References
Similar Local Cases
Entrust: Failure to revoke a certificate
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: SSL Certificates issued with Un-verified IP Addresses
Entrust: IP Address in dNSName form
Entrust: Late revocation of underscore certificate
Entrust: Incorrect keyUsage for ECC certificate
Entrust: EV Certificate missing Issuer’s EV Policy OID
Entrust: Certificate issued with '-' in ST field