← Entrust cases
Bugzilla #1673119 Self Reported Incident

Entrust: Subscriber provides private key with CSR

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust reported a compliance issue where a subscriber provided a private key along with a Certificate Signing Request (CSR), leading to the issuance of certificates with compromised keys. The issue was discovered on October 19, 2020, during a support escalation. Entrust took immediate action by revoking affected certificates and updating their systems to prevent future occurrences. A total of 121 certificates from Entrust and 12 from AffirmTrust were identified as problematic. The CA has since ceased issuing certificates with private keys included in CSRs and implemented stricter validation measures.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.90 15 comments
Chronology
  1. Entrust discovers private key was provided with CSR, leading to certificate revocation.
  2. All affected certificates were revoked and a patch was installed to reject CSRs with extra data.
Thread Activity
  1. Entrust representative — Entrust compliance team reported the issue and outlined the timeline of actions taken.
  2. Community commenter — Acknowledged the importance of the report and suggested methods for other CAs to check for similar issues.
  3. Entrust representative — Provided updates on the investigation and measures taken to prevent future occurrences.
  4. Mozilla representative — Indicated that the bug can be closed as all issues have been addressed.
Participants
Community commenter
External References
Similar Local Cases
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 100% similar
Entrust: Certificate issued with validity greater than 825-days
#1512018 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-12-04 · Closed 2023-02-22 · 99% similar
Entrust: Certificate issued with '-' in ST field
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 99% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1648472 RESOLVED Self Reported Incident Opened 2020-06-25 · Closed 2024-06-30 · 99% similar
Entrust: SHA-256 hash algorithm used with ECC P-384 key
#1635096 RESOLVED Self Reported Incident Opened 2020-05-04 · Closed 2023-02-22 · 89% similar
Entrust: Printable String Constraint Failure
#1914999 RESOLVED Self Reported Incident Opened 2024-08-26 · Closed 2025-02-28 · 88% similar
Entrust: S/MIME OrgID Country not matching C field
#1897630 RESOLVED Self Reported Incident Opened 2024-05-19 · Closed 2024-08-15 · 85% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates
#1448986 RESOLVED Self Reported Incident Opened 2018-03-26 · Closed 2023-02-22 · 84% similar
Entrust: IP Address in dNSName form

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action