← Entrust cases
Bugzilla #1766525
Certificate Problem Report
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
RESOLVED
FIXED
Entrust
AI Summary
Entrust identified a TLS certificate issued with a key potentially affected by the Close Primes vulnerability on April 25, 2022. Following the detection, an investigation confirmed the issue, leading to the revocation of the certificate within 24 hours. Entrust had not halted issuance of certificates but committed to enhancing their detection mechanisms. The Close Primes detection feature was successfully integrated into their CSR checker by August 23, 2022, and no further instances were reported.
Chronology
- Post-issuance linter detected a TLS certificate impacted by Close Primes vulnerability.
- Certificate revoked within 24 hours after confirmation of the issue.
- Close Primes detection added to CSR parser.
Participants
Bruce Morton
B. Wilson
Aaron
External References
Similar Local Cases
Entrust: Test Website Certificates Expired
Entrust: Delayed incident report - CPS typographical (text placement) error
Entrust: Late Revocation for SSL Certificates issued with Un-verified IP Addresses
Entrust: OCSP response signed with SHA-1
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
Entrust: IP Address in dNSName form
Entrust: EV Certificate missing Issuer’s EV Policy OID
Entrust: Incomplete privileged access removal within 24 hours