← Entrust cases
Bugzilla #1748634
Ca Certificate Compliance
Delayed Revocation
Remediation Tracking
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
RESOLVED
FIXED
Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Entrust's late revocation of SSL certificates that were issued without proper IP address verification. The issue was initially discovered through an internal audit and reported in a separate Bugzilla case. Entrust revoked 10 out of 12 affected certificates and later acknowledged that two certificates should have been revoked as well. The CA has since updated its practices to prevent future occurrences of retroactive validation, which contributed to the late revocation. The case has been resolved with Entrust committing to improved compliance measures.
Chronology
- Entrust advised subscribers of the impending revocation of certificates.
- Entrust revoked 10 certificates and verified IP addresses for 2 certificates.
Thread Activity
- Entrust representative — Entrust reported the incident and outlined the timeline of actions taken.
- Thisisntrocket representative — Questioned Entrust's decision-making regarding retroactive validation.
- Entrust representative — Clarified that Entrust did not consider the two certificates problematic after retroactive verification.
- Entrust representative — Proposed closure of the incident as no further updates were available.
- Community commenter — Highlighted concerns about Entrust's decision-making process and systemic issues.
- Entrust representative — Confirmed that Entrust has changed its policy to prevent retroactive validation.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Entrust: Late Revocation due to SHA-256 hash algorithm
Entrust: Late revocation of underscore certificate
Entrust: Delayed reporting of Jurisdiction issue in some EV TLS & Code Signing certificates
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
Entrust: Delayed Revocation for S/MIME certificates
Entrust: Late mis-issue certificate revocation
Entrust: Failure to revoke a certificate
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri