← Entrust cases
Bugzilla #1635096 Self Reported Incident

Entrust: Printable String Constraint Failure

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust Datacard's compliance team discovered a misissuance of an SSL certificate that included quotation marks in the printable string format within the Organization field of the Subject DN. The issue was identified on April 30, 2020, and the certificate was subsequently revoked on May 1, 2020. Entrust acknowledged that their CA software had a bug causing this misissuance and outlined steps to prevent future occurrences, including migrating to updated software. The OCSP system was patched to revoke the certificate by serial number, and updates to linting software were implemented to catch such errors in the future. The case has been resolved with the necessary fixes applied.

Model: gpt-4o-mini Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 18:46 UTC Confidence: 0.90 16 comments
Chronology
  1. Entrust discovered an SSL certificate was issued with a constraint failure.
  2. The problematic certificate was revoked.
  3. The OCSP system was patched to allow revocation by serial number.
Thread Activity
  1. Entrust representative — Entrust reported a compliance failure regarding an SSL certificate issued with quotation marks in the Organization field.
  2. Fastly representative — Wayne Thayer asked for clarification on the OCSP response and prevention measures.
  3. Entrust representative — Bruce Morton confirmed that the OCSP system has been patched and the certificate has been revoked.
  4. Mozilla representative — Ben Wilson indicated that the case could be closed.
Participants
Community commenter
External References
Similar Local Cases
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 100% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 99% similar
Entrust: Certificate issued with validity greater than 825-days
#1512018 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-12-04 · Closed 2023-02-22 · 93% similar
Entrust: Certificate issued with '-' in ST field
#1648472 RESOLVED Self Reported Incident Opened 2020-06-25 · Closed 2024-06-30 · 90% similar
Entrust: SHA-256 hash algorithm used with ECC P-384 key
#1673119 RESOLVED Self Reported Incident Opened 2020-10-23 · Closed 2023-02-22 · 89% similar
Entrust: Subscriber provides private key with CSR
#1914999 RESOLVED Self Reported Incident Opened 2024-08-26 · Closed 2025-02-28 · 88% similar
Entrust: S/MIME OrgID Country not matching C field
#1448986 RESOLVED Self Reported Incident Opened 2018-03-26 · Closed 2023-02-22 · 83% similar
Entrust: IP Address in dNSName form
#1897630 RESOLVED Self Reported Incident Opened 2024-05-19 · Closed 2024-08-15 · 82% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action