← Entrust cases
Bugzilla #1744827
Certificate Problem Report
Entrust: SSL Certificates issued with Un-verified IP Addresses
RESOLVED
FIXED
Entrust
AI Summary
Entrust identified an issue where two EV SSL certificates were issued with un-verified IP addresses in the subjectAltName extension. The problem was discovered on December 6, 2021, during a post-linting check, which led to an investigation revealing a bug in the validation process. Entrust revoked the affected certificates and implemented a patch to prevent future occurrences. The incident raised concerns regarding compliance with Baseline Requirements, particularly around the timely revocation of misissued certificates.
Chronology
- Entrust's post-issuance linter indicated that 2 EV SSL certificates were issued with un-verified IP addresses.
- All affected certificates were revoked.
- Automated negative test case for IP addresses was deployed.
Participants
Bruce Morton
Ben Wilson
Rob
Ryan Sleevi
Paul van Brouwershaven
Matthias
External References
Similar Local Cases
Entrust: Printable String Constraint Failure
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Entrust: EV Certificate missing Issuer’s EV Policy OID
Entrust: Failure to revoke a certificate
Entrust: Incorrect keyUsage for ECC certificate
Entrust: IP Address in dNSName form
Entrust: EV TLS Certificate incorrect jurisdiction