← Entrust cases
Bugzilla #1651481 Delayed Revocation

Entrust: Late Revocation due to SHA-256 hash algorithm

RESOLVED FIXED Entrust
AI Summary

Entrust experienced a late revocation incident involving 606 SSL certificates that were issued with an incorrect hash algorithm (SHA-256 instead of the required SHA-384). The issue was discovered on June 17, 2020, and after an internal review, Entrust decided to revoke the certificates but delayed the action due to concerns about potential impacts on their enterprise customers. The final 17 certificates were revoked on August 7, 2020, after a series of notifications and extensions were provided to affected subscribers. Entrust acknowledged the need for improved adherence to revocation timelines in future incidents.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Confidence: 0.90
Chronology
  1. Issue discovered using crt.sh linting software.
  2. Last CA configured to support SHA-384 signing.
  3. Plan changed to revoke all certificates.
  4. Subscribers requested to revoke certificates.
  5. Final 17 certificates revoked.
Participants
Bruce Morton Ryan Sleevi Ben Wilson
Similar Local Cases
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 60% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1804753 RESOLVED Delayed Revocation Opened 2022-12-08 · Closed 2023-04-19 · 60% similar
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction
#1647099 RESOLVED Delayed Revocation Opened 2020-06-20 · Closed 2023-02-22 · 58% similar
Camerfirma: Delayed revocations related to Invalid authorityKeyIdentifier - recurrent incident
#1651828 RESOLVED Delayed Revocation Opened 2020-07-09 · Closed 2023-02-22 · 56% similar
DigiCert: Delay of revocation for EV audit inconsistency incident
#1707229 RESOLVED Delayed Revocation Opened 2021-04-23 · Closed 2023-02-22 · 56% similar
SECOM: Delayed Revocation of non-technically constrained FUJIFILM Certificates
#1652610 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 55% similar
SECOM: Delayed Revocation of CA Certificate with OCSP EKU Issue
#1652604 RESOLVED Delayed Revocation Opened 2020-07-13 · Closed 2023-02-22 · 54% similar
PKIoverheid: Failure to revoke within 7 days: OCSP EKU issue
#1670861 RESOLVED Delayed Revocation Opened 2020-10-13 · Closed 2023-02-22 · 53% similar
Actalis: delayed revocation related to inaccurate value in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action