← Entrust cases
Bugzilla #1737057 Technical Compliance

Entrust: CRLs and OCSP responses not issued as specified in the CPS

RESOLVED FIXED Entrust
AI Summary

Entrust identified an issue where Certificate Revocation Lists (CRLs) and Online Certificate Status Protocol (OCSP) responses were issued with a validity period exceeding the maximum specified in their Certificate Practice Statement (CPS) by one second. This discrepancy was discovered through a review of Mozilla Incident Reports. Although no certificates were mis-issued, Entrust took corrective action by re-issuing the affected root CRLs and OCSP responses to ensure compliance. The issue was resolved, and Entrust plans to update their CPS based on forthcoming CA/Browser Forum requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Confidence: 1.00
Chronology
  1. Google Trust Services files incident Bug 1731164
  2. Investigation into incidents initiated
  3. Full incident report posted
  4. Root CRLs and OCSP responses re-issued to comply with CPS
Participants
Bruce Morton Ben Wilson
External References
Similar Local Cases
#1428891 RESOLVED Technical Compliance Opened 2018-01-08 · Closed 2023-02-22 · 61% similar
Entrust: Non-BR-Compliant OCSP Responder
#1684112 RESOLVED Technical Compliance Opened 2020-12-23 · Closed 2023-02-22 · 49% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1905072 RESOLVED Technical Compliance Opened 2024-06-27 · Closed 2024-08-22 · 48% similar
Turn off Secure Email Trust Bit for certSIGN ROOT CA G2 cert
#1771722 RESOLVED Technical Compliance Opened 2022-05-30 · Closed 2023-02-22 · 47% similar
Firmaprofesional: 2022 - Title field
#1716902 RESOLVED Technical Compliance Opened 2021-06-17 · Closed 2023-02-22 · 47% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1436173 RESOLVED Technical Compliance Opened 2018-02-06 · Closed 2023-02-22 · 47% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
#1943135 RESOLVED Technical Compliance Opened 2025-01-22 · Closed 2025-05-25 · 46% similar
Request to disable SMIME "trust bit" for GoDaddy CAs
#1832338 RESOLVED Technical Compliance Opened 2023-05-10 · Closed 2023-06-08 · 46% similar
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action