← Entrust cases
Bugzilla #1731887 Incident

Entrust: Test Website Certificates Expired

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Entrust test website certificates that expired. Entrust said it reviewed prior incident reports (Bugzilla 1730291 and 1726333) and realized it had similar expired test website certificate incidents but did not understand that an incident report was required. Entrust stated it will update its policy and practices to ensure expired test website certificates are treated as incidents and that future compliance requirements are covered. Entrust provided a timeline, including awareness of expired certificates in September 2019 and March 2020, and said it completed a migration project in May 2020 and reissued the expired test certificates on 29 May 2020. Entrust also stated the incident did not affect certificate issuance and described new operational controls, including issuing test CAs on the same platform as customer CAs, using an enterprise account with 60/30/10-day expiry notifications, and implementing monitoring for test website certificates. Mozilla closed the bug as FIXED/RESOLVED after reviewing the incident report and questions raised in the thread.

Model: gpt-5.4-nano Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.86 6 comments
Chronology
  1. Entrust became aware that eight certificates supporting AffirmTrust root test sites had expired.
  2. Entrust became aware that two certificates supporting Entrust root test sites had expired.
  3. Entrust completed a migration project for test CAs and reissued expired test certificates.
  4. Entrust opened the bug to disclose the expired test certificate incident and commit to policy/practice updates.
Thread Activity
  1. Entrust representative — Entrust disclosed that test website certificates had expired, said it previously misunderstood the need to file an incident report, and committed to update its policy and provide a full incident report by 28 September 2021.
  2. Thisisntrocket representative — A reviewer asked for information on how the misunderstanding occurred and how it was not detected earlier.
  3. Entrust representative — Entrust explained that earlier practices focused on mis-issued certificates and that it missed that expiring test website certificates should be treated as an incident, but said it recognized this via monitoring incident reports and would update practices.
  4. Entrust representative — Entrust provided detailed incident information, including awareness dates, actions taken (migration and reissuance), and future controls to prevent test website certificate expiry.
  5. Mozilla representative — Mozilla commented that the incident report was helpful, referenced a resource for test websites, and asked whether additional lessons could be learned.
  6. Mozilla representative — Mozilla stated it would close the bug on 20-Oct-2021.
Participants
Entrust representative Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1737057 RESOLVED Incident Opened 2021-10-21 · Closed 2023-02-22 · 96% similar
Entrust: CRLs and OCSP responses not issued as specified in the CPS
#1890123 RESOLVED Incident Opened 2024-04-06 · Closed 2024-08-13 · 95% similar
Entrust: Failed to provide a preliminary incident report according to TLS BR 4.9.5
#1889217 RESOLVED Incident Opened 2024-04-02 · Closed 2024-07-01 · 78% similar
Entrust: CRL non-conformance with the TLS BRs
#1730291 RESOLVED Incident Opened 2021-09-11 · Closed 2024-06-30 · 77% similar
Apple: Test website certificates expired
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 76% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1716902 RESOLVED Incident Opened 2021-06-17 · Closed 2023-02-22 · 76% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 76% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1686524 RESOLVED Self Reported Incident Incident Opened 2021-01-13 · Closed 2023-02-22 · 75% similar
Camerfirma: Certificate issued with 3-year lifespan, unknown policy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action