← Entrust cases
Bugzilla #1651481
Delayed Revocation
Entrust: Late Revocation due to SHA-256 hash algorithm
RESOLVED
FIXED
Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Entrust reported a late revocation incident involving 606 SSL certificates that were incorrectly signed using SHA-256 instead of the required SHA-384. The issue was discovered on June 17, 2020, and despite initially planning to allow the certificates to expire, Entrust decided to revoke them after further review. The CA communicated with affected subscribers and set a deadline for revocation, which was ultimately completed by August 7, 2020. The incident raised concerns regarding Entrust's adherence to revocation timelines as outlined in Mozilla's policies.
Chronology
- Entrust discovered the issue with SHA-256 signed certificates.
- All certificates signed with the incorrect hashing algorithm were revoked.
Thread Activity
- Entrust representative — User Agent: Mozilla/5.0... Certificates are being revoked after the 5 day requirement.
- Community commenter — Expressed concerns about Entrust's rationale for delayed revocation.
- Entrust representative — Status: The final 17 certificates were revoked on 7 August 2020.
Participants
Community commenter
External References
Similar Local Cases
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Entrust: Late Revocation for Invalid State/Province Issue
Entrust: Delayed reporting of Jurisdiction issue in some EV TLS & Code Signing certificates
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
Entrust: Failure to revoke a certificate
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
Entrust: Delayed Revocation for S/MIME certificates