← Entrust cases
Bugzilla #1675295 Other

Entrust: Invalid data in commonName fields

RESOLVED INVALID Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The reporter stated that Entrust had issued certificates with invalid data in the commonName field and provided multiple crt.sh links to examples. The reporter noted that some of these certificates had been revoked and that they could not find an incident posted in Mozilla’s CA Program. They also said they did not find certificates issued after 2020-08-17 (the revocation date in one linked certificate), suggesting the issue may have been fixed for new issuances. Another participant responded that the certificates were not issued by an SSL-enabled CA and did not use BR profile identifiers, and that they were issued under Entrust’s “Verified Mark Certificates” profile of Entrust’s CPS using the VMC Guidelines. The participant concluded they believed this was not a problem in the scope of Mozilla’s root store. The reporter agreed and closed the bug as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 21:27 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.62 4 comments
Chronology
  1. A bug was filed alleging Entrust-issued certificates contained invalid commonName data.
  2. The issue was reviewed and determined to be outside the scope of Mozilla’s root store.
Thread Activity
  1. Fozzie representative — Reported that Entrust issued certificates with invalid commonName data, provided crt.sh links, and noted some were revoked.
  2. Fozzie representative — Said they did not find certificates issued after 2020-08-17 and believed the issue was fixed for new issuances.
  3. Thisisntrocket representative — Explained the certificates were issued under Entrust’s “Verified Mark Certificates” profile (not an SSL-enabled CA) and believed it was not in the scope of Mozilla’s root store.
  4. Fozzie representative — Agreed with the assessment and closed the bug as INVALID.
Participants
Fozzie representative Entrust representative Thisisntrocket representative
Similar Local Cases
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 41% similar
Entrust: EV TLS Certificate incorrect jurisdiction
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 40% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1731887 RESOLVED Incident Opened 2021-09-21 · Closed 2023-02-22 · 40% similar
Entrust: Test Website Certificates Expired
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 40% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1268225 RESOLVED Ca Certificate Compliance Opened 2016-04-27 · Closed 2022-11-14 · 35% similar
entrust: Invalid Teletext strings

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action