← Entrust cases
Bugzilla #1667448 Certificate Misissuance

Entrust: Incorrect keyUsage for ECC certificate

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On 25 September 2020, Entrust’s compliance team discovered via post-issuance linting that an ECC SSL certificate had been issued with a keyUsage value of keyEncipherment. Entrust stated that it interpreted the CA/B Baseline Requirements and RFC 5480 such that ECC SSL subscriber certificates should not include keyEncipherment, and that the certificate should have used an allowed combination such as digitalSignature, nonRepudiation, and/or keyAgreement. Entrust said the issue occurred when a Retail OV ECC SSL certificate request was not blocked and was routed to a CA configured to issue subscriber certificates with RSA keys, resulting in the incorrect keyUsage being signed. Entrust initiated revocation for the affected certificate after receiving a subscriber revocation request at 25 September 2020 8:50 UTC, and it began investigating the issue. Entrust later reported remediation steps: updating zlint to the latest version and updating pre-issuance linting code so that incorrect keyUsage would produce an error and stop certificate issuance. Entrust stated that effective 23 October 2020, zlint was updated and pre-issuance linting would block future incorrect keyUsage, and the bug was set to be closed on or about 30 October 2020 unless further issues were discussed. The bug’s resolution is FIXED and the current status is RESOLVED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:24 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.86 9 comments
Chronology
  1. Entrust issued an ECC SSL certificate with keyUsage set to keyEncipherment and later revoked it after a subscriber revocation request.
  2. Entrust updated zlint and updated pre-issuance linting code to block future issuance when keyUsage is incorrect.
Thread Activity
  1. Entrust representative — Entrust reported that post-issuance linting found an ECC SSL certificate with keyUsage=keyEncipherment, described the suspected routing/enrollment path that allowed the request through, and stated a revocation was performed.
  2. Community commenter — Ryan asked Entrust to factor in related prior bugs/discussions into the timeline.
  3. Entrust representative — Bruce responded that the referenced issues did not apply to Entrust’s root cause as described, and said the current issue was a bug in enrollment software that sent an ECC key request to an RSA-configured CA.
  4. Community commenter — Ryan asked for a remediation timeline and discussed how controls should be evaluated across CAs.
  5. Entrust representative — Bruce stated remediation would include correcting the Retail ECC handling, updating zlint, and updating code so pre-issuance linting would error and stop issuance; he gave a remediation target no later than 30 October 2020.
  6. Entrust representative — Bruce reported that zlint was updated effective 23 October 2020 and pre-issuance linting code would stop issuance on incorrect keyUsage, stating actions were completed.
  7. Mozilla representative — Mozilla indicated it would close the bug on or about 30-Oct-2020 unless other issues remained.
Participants
Entrust representative Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 98% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 97% similar
Entrust: EV TLS Certificate cPSuri missing
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 97% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1918380 RESOLVED Certificate Misissuance Opened 2024-09-12 · Closed 2024-11-06 · 96% similar
Entrust: Business Entity not permitted in CPS
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 95% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#1567659 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 95% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 86% similar
Entrust: IP in dnsName
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 84% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action