Entrust: Invalid data in State/Province Field
Entrust disclosed that it had issued certificates with invalid state/province data and opened this bug to track the incident and remediation. The issue was first identified after a third party reported potentially invalid state/province values on 2020-08-10, and Entrust confirmed the report was accurate. Entrust said 397 OV SSL certificates were impacted in the initial incident, with 395 tied to one large organization and 2 tied to other organizations, and it notified the affected organizations that revocation was required within 5 days. Entrust later reported additional certificates found through its own scans, including 145 certificates in October 2020, 6 more in April 2021, and 2 more in May 2021, each scheduled for revocation under the BR timeline. As remediation, Entrust described changes to its vetting system, including replacing the free-text state/province field with ISO 3166-2-based drop-downs and adding post-issuance linting checks. The bug was resolved with FIXED, and Mozilla indicated it intended to close the bug after the remaining updates were complete.
- First problematic OV SSL certificate in the incident was issued.
- Last certificate in the initial 397-certificate set was issued.
- Entrust received a third-party report about invalid state/province data in issued certificates.
- Entrust notified the three affected organizations that their certificates had to be revoked within 5 days.
- The two certificates not belonging to the large organization were revoked.
- The remaining 21 certificates from the initial incident were revoked.
- Entrust reported 145 additional certificates with invalid state/province values and set a revocation deadline.
- ISO 3166-2 state/province drop-downs went live in Entrust's system.
- Entrustdatacard representative — Entrust opened the bug and said it had discovered certificates with invalid state/province data after a third-party report.
- Entrustdatacard representative — Entrust said the two certificates not belonging to the large organization had been revoked.
- Entrustdatacard representative — Entrust described planned system changes to replace the text field with a country-based state/province drop-down and add linting checks.
- Entrustdatacard representative — Entrust said the root cause for the first case was human error combined with a system that allowed arbitrary state/province text entry, and it said it would implement false-positive testing for reviewers.
- Entrustdatacard representative — Entrust reported a scan found 145 certificates with invalid state/province values and set a revocation deadline for them.
- Entrustdatacard representative — Entrust reported 6 more certificates with incorrect stateOrProvince values and said the system update had been delayed to May 12.
- Entrustdatacard representative — Entrust said the ISO 3166-2 state/province drop-downs were now live and would be used for all verifications going forward.
- Mozilla representative — Mozilla said it intended to close the bug on or about 2021-06-04 unless unresolved issues remained.