← Entrust cases
Bugzilla #1648472 Certificate Misissuance

Entrust: SHA-256 hash algorithm used with ECC P-384 key

RESOLVED FIXED Entrust
AI Summary

Entrust Datacard discovered that 16 SSL certificates were issued using an ECC P-384 key but signed with the SHA-256 algorithm, contrary to Mozilla Policy v2.7, which requires SHA-384 for such keys. The issue was identified on June 17, 2020, through linting software, leading to an investigation and subsequent migration of the affected CAs to support SHA-384 signing. Entrust has pledged to notify subscribers and offer certificate re-issues at no cost, although they do not plan to revoke the misissued certificates, citing that they still provide adequate security.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 0.90
Chronology
  1. Issue discovered using crt.sh linting software.
  2. L1J CA configured to support SHA-384 signing.
Participants
Bruce Morton Ryan Sleevi
External References
Similar Local Cases
#1524876 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 67% similar
Entrust: IP in dnsName
#1673119 RESOLVED Certificate Misissuance Opened 2020-10-23 · Closed 2023-02-22 · 66% similar
Entrust: Subscriber provides private key with CSR
#1520876 RESOLVED Certificate Misissuance Opened 2019-01-17 · Closed 2023-02-22 · 66% similar
Entrust: Late mis-issue certificate revocation
#1535735 RESOLVED Certificate Misissuance Opened 2019-03-15 · Closed 2023-02-22 · 66% similar
Entrust: Issued Certificates to incorrect Organization
#1561013 RESOLVED Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 65% similar
Entrust: Certificate issued with validity greater than 825-days
#1567659 RESOLVED Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 65% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1552562 RESOLVED Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 64% similar
Entrust: Question marks in certificate O and L fields
#1890896 RESOLVED Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 60% similar
Entrust: CPS typographical (text placement) error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action