← Entrust cases
Bugzilla #1648472 Self Reported Incident

Entrust: SHA-256 hash algorithm used with ECC P-384 key

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust Datacard discovered that 16 SSL certificates were issued using an ECC P-384 key but signed with the SHA-256 algorithm, contrary to Mozilla Policy v2.7, which requires SHA-384 for such keys. The issue was identified on June 17, 2020, using linting software. Entrust took corrective actions, migrating the affected CAs to support SHA-384 signing by June 24, 2020. They have opted not to revoke the certificates, citing that the security level remains acceptable. Entrust has committed to updating their processes to prevent future occurrences and will offer re-issuance of certificates to affected subscribers at no cost.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.85 22 comments
Chronology
  1. Entrust discovered the issue using linting software.
  2. Entrust migrated the affected CAs to support SHA-384 signing.
Thread Activity
  1. Entrust representative — Entrust reported the discovery of the issue and outlined the timeline of actions taken.
  2. Community commenter — Expressed concerns about the lack of detail in Entrust's incident report.
  3. Entrust representative — Provided updates to the incident report addressing previous concerns.
  4. Entrust representative — Outlined plans for implementing corrective measures and monitoring compliance.
  5. Mozilla representative — Indicated that the matter can be closed.
Participants
Community commenter
External References
Similar Local Cases
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 100% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1512018 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-12-04 · Closed 2023-02-22 · 99% similar
Entrust: Certificate issued with '-' in ST field
#1673119 RESOLVED Self Reported Incident Opened 2020-10-23 · Closed 2023-02-22 · 99% similar
Entrust: Subscriber provides private key with CSR
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 97% similar
Entrust: Certificate issued with validity greater than 825-days
#1635096 RESOLVED Self Reported Incident Opened 2020-05-04 · Closed 2023-02-22 · 90% similar
Entrust: Printable String Constraint Failure
#1914999 RESOLVED Self Reported Incident Opened 2024-08-26 · Closed 2025-02-28 · 88% similar
Entrust: S/MIME OrgID Country not matching C field
#1897630 RESOLVED Self Reported Incident Opened 2024-05-19 · Closed 2024-08-15 · 83% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1448986 RESOLVED Self Reported Incident Opened 2018-03-26 · Closed 2023-02-22 · 83% similar
Entrust: IP Address in dNSName form

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action