Entrust: Subscriber provides private key with CSR
Entrust reported a compliance issue where a subscriber provided a private key along with a Certificate Signing Request (CSR), leading to the issuance of certificates with compromised keys. The issue was discovered on October 19, 2020, during a support escalation. Entrust took immediate action by revoking affected certificates and updating their systems to prevent future occurrences. A total of 121 certificates from Entrust and 12 from AffirmTrust were identified as problematic. The CA has since ceased issuing certificates with private keys included in CSRs and implemented stricter validation measures.
- Entrust discovers private key was provided with CSR, leading to certificate revocation.
- All affected certificates were revoked and a patch was installed to reject CSRs with extra data.
- Entrust representative — Entrust compliance team reported the issue and outlined the timeline of actions taken.
- Community commenter — Acknowledged the importance of the report and suggested methods for other CAs to check for similar issues.
- Entrust representative — Provided updates on the investigation and measures taken to prevent future occurrences.
- Mozilla representative — Indicated that the bug can be closed as all issues have been addressed.