Entrust: SHA-256 hash algorithm used with ECC P-384 key
Entrust Datacard discovered that 16 SSL certificates were issued using an ECC P-384 key but signed with the SHA-256 algorithm, contrary to Mozilla Policy v2.7, which requires SHA-384 for such keys. The issue was identified on June 17, 2020, using linting software. Entrust took corrective actions, migrating the affected CAs to support SHA-384 signing by June 24, 2020. They have opted not to revoke the certificates, citing that the security level remains acceptable. Entrust has committed to updating their processes to prevent future occurrences and will offer re-issuance of certificates to affected subscribers at no cost.
- Entrust discovered the issue using linting software.
- Entrust migrated the affected CAs to support SHA-384 signing.
- Entrust representative — Entrust reported the discovery of the issue and outlined the timeline of actions taken.
- Community commenter — Expressed concerns about the lack of detail in Entrust's incident report.
- Entrust representative — Provided updates to the incident report addressing previous concerns.
- Entrust representative — Outlined plans for implementing corrective measures and monitoring compliance.
- Mozilla representative — Indicated that the matter can be closed.