← Entrust cases
Bugzilla #1748634 Ca Certificate Compliance Delayed Revocation Remediation Tracking

Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Entrust's late revocation of SSL certificates that were issued without proper IP address verification. The issue was initially discovered through an internal audit and reported in a separate Bugzilla case. Entrust revoked 10 out of 12 affected certificates and later acknowledged that two certificates should have been revoked as well. The CA has since updated its practices to prevent future occurrences of retroactive validation, which contributed to the late revocation. The case has been resolved with Entrust committing to improved compliance measures.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.85 15 comments
Chronology
  1. Entrust advised subscribers of the impending revocation of certificates.
  2. Entrust revoked 10 certificates and verified IP addresses for 2 certificates.
Thread Activity
  1. Entrust representative — Entrust reported the incident and outlined the timeline of actions taken.
  2. Thisisntrocket representative — Questioned Entrust's decision-making regarding retroactive validation.
  3. Entrust representative — Clarified that Entrust did not consider the two certificates problematic after retroactive verification.
  4. Entrust representative — Proposed closure of the incident as no further updates were available.
  5. Community commenter — Highlighted concerns about Entrust's decision-making process and systemic issues.
  6. Entrust representative — Confirmed that Entrust has changed its policy to prevent retroactive validation.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1651481 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 100% similar
Entrust: Late Revocation due to SHA-256 hash algorithm
#1521520 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-21 · Closed 2023-02-22 · 89% similar
Entrust: Late revocation of underscore certificate
#1898847 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2024-08-15 · 81% similar
Entrust: Delayed reporting of Jurisdiction issue in some EV TLS & Code Signing certificates
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 80% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1910237 RESOLVED Delayed Revocation Closure Request Opened 2024-07-27 · Closed 2025-05-13 · 80% similar
Entrust: Delayed Revocation for S/MIME certificates
#1520876 RESOLVED Ca Certificate Compliance Delayed Revocation Opened 2019-01-17 · Closed 2023-02-22 · 80% similar
Entrust: Late mis-issue certificate revocation
#1636339 RESOLVED Delayed Revocation Opened 2020-05-08 · Closed 2023-02-22 · 80% similar
Entrust: Failure to revoke a certificate
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 79% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action