← Entrust cases
Bugzilla #1673119 Certificate Misissuance

Entrust: Subscriber provides private key with CSR

RESOLVED FIXED Entrust
AI Summary

Entrust reported a significant incident where a subscriber inadvertently included a private key with their Certificate Signing Request (CSR), leading to the issuance of 121 compromised certificates. The issue was identified on October 19, 2020, and subsequent investigations revealed that the same private key had been used in previous requests. Entrust promptly revoked all affected certificates and implemented a patch to prevent future occurrences. The incident highlighted the need for stricter validation of CSRs to avoid similar misissuances.

Model: gpt-4o-mini Generated: 2026-06-13 21:26 UTC Confidence: 0.95
Chronology
  1. Entrust discovers private key included with CSR.
  2. Trigger Certificate revoked.
  3. All affected certificates confirmed revoked.
  4. Patch installed to reject CSRs with extra data.
Participants
Bruce Morton Ryan Sleevi Jeremy Rowley Matthias Adriano Santoni B. Wilson
External References
Similar Local Cases
#1906467 RESOLVED Certificate Misissuance Opened 2024-07-05 · Closed 2025-05-13 · 70% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1890896 RESOLVED Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 69% similar
Entrust: CPS typographical (text placement) error
#1535735 RESOLVED Certificate Misissuance Opened 2019-03-15 · Closed 2023-02-22 · 69% similar
Entrust: Issued Certificates to incorrect Organization
#1561013 RESOLVED Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 68% similar
Entrust: Certificate issued with validity greater than 825-days
#1567659 RESOLVED Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 68% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1552562 RESOLVED Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 67% similar
Entrust: Question marks in certificate O and L fields
#1520876 RESOLVED Certificate Misissuance Opened 2019-01-17 · Closed 2023-02-22 · 66% similar
Entrust: Late mis-issue certificate revocation
#1524876 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 66% similar
Entrust: IP in dnsName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action