← Entrust cases
Bugzilla #1748634
Certificate Problem Report
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
RESOLVED
FIXED
Entrust
AI Summary
Entrust reported a late revocation incident involving SSL certificates issued without proper IP address verification. Initially, 12 certificates were issued without verification, leading to the revocation of 10 certificates and the retroactive verification of 2. Entrust acknowledged the mistake of not revoking the two certificates initially and has since updated its practices to prevent future occurrences of retroactive validation. The incident was resolved with a commitment to adhere to proper verification protocols moving forward.
Chronology
- Subscribers were advised of impending revocation of certificates.
- Certificates were officially revoked.
- Incident reported in Bugzilla.
- Case marked as resolved.
Participants
Bruce Morton
Matthias
B. Wilson
Ryan Sleevi
External References
Similar Local Cases
Entrust: SSL Certificates issued with Un-verified IP Addresses
Entrust: Test Website Certificates Expired
Entrust: IP Address in dNSName form
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: Failure to revoke a certificate
Entrust: Printable String Constraint Failure
Entrust: Delayed incident report - CPS typographical (text placement) error
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability