Entrust: Invalid data in commonName fields
The reporter stated that Entrust had issued certificates with invalid data in the commonName field and provided multiple crt.sh links to examples. The reporter noted that some of these certificates had been revoked and that they could not find an incident posted in Mozilla’s CA Program. They also said they did not find certificates issued after 2020-08-17 (the revocation date in one linked certificate), suggesting the issue may have been fixed for new issuances. Another participant responded that the certificates were not issued by an SSL-enabled CA and did not use BR profile identifiers, and that they were issued under Entrust’s “Verified Mark Certificates” profile of Entrust’s CPS using the VMC Guidelines. The participant concluded they believed this was not a problem in the scope of Mozilla’s root store. The reporter agreed and closed the bug as INVALID.
- A bug was filed alleging Entrust-issued certificates contained invalid commonName data.
- The issue was reviewed and determined to be outside the scope of Mozilla’s root store.
- Fozzie representative — Reported that Entrust issued certificates with invalid commonName data, provided crt.sh links, and noted some were revoked.
- Fozzie representative — Said they did not find certificates issued after 2020-08-17 and believed the issue was fixed for new issuances.
- Thisisntrocket representative — Explained the certificates were issued under Entrust’s “Verified Mark Certificates” profile (not an SSL-enabled CA) and believed it was not in the scope of Mozilla’s root store.
- Fozzie representative — Agreed with the assessment and closed the bug as INVALID.