Entrust: TLS certificate issued with a key potentially impacted by the Close Primes vulnerability
Entrust reported that it became aware on 25 April 2022 that a TLS certificate had been issued with a key potentially impacted by the Close Primes vulnerability, based on a post-issuance linting check. Entrust began investigating on 25 April 2022 and confirmed on 26 April 2022 that the key was impacted. Entrust requested revocation within 24 hours under BR 4.9.1.1 (4), and the certificate was revoked by the subscriber on 26 April 2022 at 14:22 UTC. Entrust stated it had not stopped issuance and explained that issuance was not prevented because close-primes detection was not implemented in pre-issuance linting and the CSR checker work was still on backlog. Entrust said it would re-prioritize development of close-primes detection in its CSR checker and created a zlint issue to implement a close-primes lint. Entrust later reported that close-primes detection was added to its CSR parser on 23 August 2022, no other close-primes instances were detected, and it believed the incident report was complete; Mozilla indicated it would close the bug on 26-Aug-2022. The bug is marked RESOLVED with resolution FIXED.
- Sectigo informed other CAs of an issue with weak RSA keys.
- Post-issuance detection of Close Primes was released to production.
- Post-issuance linter detected a TLS certificate that could be impacted by the Close Primes vulnerability.
- The impacted certificate was revoked by the subscriber after Entrust requested revocation.
- Close Primes detection was added to Entrust’s CSR parser.
- Entrust representative — Entrust described how it discovered the issue via post-issuance linting, confirmed the key was impacted, requested revocation within 24 hours, and reported the certificate was revoked; it also outlined remediation steps including re-prioritizing close-primes detection in the CSR checker and linking to a zlint issue.
- Entrust representative — Entrust said it would follow up by 27 May 2022 to estimate when close-primes detection would be added to the CSR checker and would monitor CA/Browser Forum actions.
- Entrust representative — Entrust stated close-primes detection would be added to the CSR checker by October 2022 and that it would continue post-linting monitoring and revoke for future occurrences.
- Entrust representative — Entrust reported close-primes detection was added to its CSR parser on 23 August 2022, no other instances were detected, and it believed the incident report was complete.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 26-Aug-2022.
- Internet Security Research Group — Let’s Encrypt shared that a close-primes lint was added to zlint and linked to the zlint pull request.