← Entrust cases
Bugzilla #1658792 Self Reported Incident

Entrust: Invalid data in State/Province Field

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust disclosed that it had issued certificates with invalid state/province data and opened this bug to track the incident and remediation. The issue was first identified after a third party reported potentially invalid state/province values on 2020-08-10, and Entrust confirmed the report was accurate. Entrust said 397 OV SSL certificates were impacted in the initial incident, with 395 tied to one large organization and 2 tied to other organizations, and it notified the affected organizations that revocation was required within 5 days. Entrust later reported additional certificates found through its own scans, including 145 certificates in October 2020, 6 more in April 2021, and 2 more in May 2021, each scheduled for revocation under the BR timeline. As remediation, Entrust described changes to its vetting system, including replacing the free-text state/province field with ISO 3166-2-based drop-downs and adding post-issuance linting checks. The bug was resolved with FIXED, and Mozilla indicated it intended to close the bug after the remaining updates were complete.

Model: gpt-5.4-mini Generated: 2026-06-13 21:23 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.98 32 comments
Chronology
  1. First problematic OV SSL certificate in the incident was issued.
  2. Last certificate in the initial 397-certificate set was issued.
  3. Entrust received a third-party report about invalid state/province data in issued certificates.
  4. Entrust notified the three affected organizations that their certificates had to be revoked within 5 days.
  5. The two certificates not belonging to the large organization were revoked.
  6. The remaining 21 certificates from the initial incident were revoked.
  7. Entrust reported 145 additional certificates with invalid state/province values and set a revocation deadline.
  8. ISO 3166-2 state/province drop-downs went live in Entrust's system.
Thread Activity
  1. Entrustdatacard representative — Entrust opened the bug and said it had discovered certificates with invalid state/province data after a third-party report.
  2. Entrustdatacard representative — Entrust said the two certificates not belonging to the large organization had been revoked.
  3. Entrustdatacard representative — Entrust described planned system changes to replace the text field with a country-based state/province drop-down and add linting checks.
  4. Entrustdatacard representative — Entrust said the root cause for the first case was human error combined with a system that allowed arbitrary state/province text entry, and it said it would implement false-positive testing for reviewers.
  5. Entrustdatacard representative — Entrust reported a scan found 145 certificates with invalid state/province values and set a revocation deadline for them.
  6. Entrustdatacard representative — Entrust reported 6 more certificates with incorrect stateOrProvince values and said the system update had been delayed to May 12.
  7. Entrustdatacard representative — Entrust said the ISO 3166-2 state/province drop-downs were now live and would be used for all verifications going forward.
  8. Mozilla representative — Mozilla said it intended to close the bug on or about 2021-06-04 unless unresolved issues remained.
Participants
Entrustdatacard representative Community commenter Fozzie representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1599484 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-11-26 · Closed 2023-02-22 · 95% similar
Entrust: EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"
#1914999 RESOLVED Self Reported Incident Opened 2024-08-26 · Closed 2025-02-28 · 90% similar
Entrust: S/MIME OrgID Country not matching C field
#1894111 RESOLVED Ca Documents Self Reported Incident Opened 2024-04-29 · Closed 2025-01-22 · 89% similar
Entrust: Not updating CPR Problem Reporting Mechanism fields in CCADB
#1921387 RESOLVED Self Reported Incident Opened 2024-09-27 · Closed 2025-03-18 · 89% similar
Entrust: Improperly Verified Business Category
#1390996 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 89% similar
Entrust: Non-BR-Compliant Certificate Issuance
#1448986 RESOLVED Self Reported Incident Opened 2018-03-26 · Closed 2023-02-22 · 89% similar
Entrust: IP Address in dNSName form
#1897630 RESOLVED Self Reported Incident Opened 2024-05-19 · Closed 2024-08-15 · 88% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1867130 RESOLVED Self Reported Incident Opened 2023-11-28 · Closed 2024-05-10 · 88% similar
Entrust: Jurisdiction Locality Wrong in EV Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action