← Entrust cases
Bugzilla #1766525 Ca Certificate Compliance Certificate Misissuance Remediation Tracking

Entrust: TLS certificate issued with a key potentially impacted by the Close Primes vulnerability

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust reported that it became aware on 25 April 2022 that a TLS certificate had been issued with a key potentially impacted by the Close Primes vulnerability, based on a post-issuance linting check. Entrust began investigating on 25 April 2022 and confirmed on 26 April 2022 that the key was impacted. Entrust requested revocation within 24 hours under BR 4.9.1.1 (4), and the certificate was revoked by the subscriber on 26 April 2022 at 14:22 UTC. Entrust stated it had not stopped issuance and explained that issuance was not prevented because close-primes detection was not implemented in pre-issuance linting and the CSR checker work was still on backlog. Entrust said it would re-prioritize development of close-primes detection in its CSR checker and created a zlint issue to implement a close-primes lint. Entrust later reported that close-primes detection was added to its CSR parser on 23 August 2022, no other close-primes instances were detected, and it believed the incident report was complete; Mozilla indicated it would close the bug on 26-Aug-2022. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:32 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.86 6 comments
Chronology
  1. Sectigo informed other CAs of an issue with weak RSA keys.
  2. Post-issuance detection of Close Primes was released to production.
  3. Post-issuance linter detected a TLS certificate that could be impacted by the Close Primes vulnerability.
  4. The impacted certificate was revoked by the subscriber after Entrust requested revocation.
  5. Close Primes detection was added to Entrust’s CSR parser.
Thread Activity
  1. Entrust representative — Entrust described how it discovered the issue via post-issuance linting, confirmed the key was impacted, requested revocation within 24 hours, and reported the certificate was revoked; it also outlined remediation steps including re-prioritizing close-primes detection in the CSR checker and linking to a zlint issue.
  2. Entrust representative — Entrust said it would follow up by 27 May 2022 to estimate when close-primes detection would be added to the CSR checker and would monitor CA/Browser Forum actions.
  3. Entrust representative — Entrust stated close-primes detection would be added to the CSR checker by October 2022 and that it would continue post-linting monitoring and revoke for future occurrences.
  4. Entrust representative — Entrust reported close-primes detection was added to its CSR parser on 23 August 2022, no other instances were detected, and it believed the incident report was complete.
  5. Mozilla representative — Mozilla stated it would close the bug on Friday, 26-Aug-2022.
  6. Internet Security Research Group — Let’s Encrypt shared that a close-primes lint was added to zlint and linked to the zlint pull request.
Participants
Entrust representative Mozilla representative Internet Security Research Group
Similar Local Cases
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 100% similar
Entrust: EV TLS Certificate cPSuri missing
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 100% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 100% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1667448 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 97% similar
Entrust: Incorrect keyUsage for ECC certificate
#1918380 RESOLVED Certificate Misissuance Opened 2024-09-12 · Closed 2024-11-06 · 96% similar
Entrust: Business Entity not permitted in CPS
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 95% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 90% similar
Entrust: EV TLS Certificate incorrect jurisdiction
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 88% similar
Entrust: IP in dnsName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action