← Entrust cases
Bugzilla #1804753 Delayed Revocation

Entrust: Delayed Revocation for EV TLS certificate incorrect jurisdiction

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Entrust’s delayed revocation of EV TLS certificates that had incorrect jurisdiction information. Entrust stated it discovered the incident in November and that revocation for some certificates was delayed due to blackout periods. Entrust reported contacting subscribers on 28 November 2022, advising them of the incident, the miss-issued certificates, and planned revocation dates, and it discussed revocation plans and status with compliance and subscribers. In response to questions about extension criteria, Entrust said it accepted subscriber requests because it was concerned that revoking during the blackout period would cause more harm to relying parties than leaving certificates in place with an EV jurisdiction error, and it stated it would not grant an extension for key compromise because compromised private keys are revoked within 24 hours of proving key compromise. Entrust provided revocation completion updates for multiple subscribers, including revocations completed on 2 December 2022, 4 December 2022, 15 January 2023, 6 February 2023, and 15 March 2023, with all certificates revoked. Mozilla indicated the incident could be closed and scheduled closure for 19-Apr-2023. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:34 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.90 10 comments
Chronology
  1. Entrust contacted subscribers about the EV TLS incorrect-jurisdiction incident and planned revocation dates.
  2. Entrust revoked Prudential Financial EV TLS certificates.
  3. Entrust completed revocation for ING Groep certificates.
  4. Entrust completed revocation for Munich Re Group certificates.
  5. Entrust revoked Azimut Holding certificates.
  6. Entrust revoked Experian certificates.
  7. Entrust revoked First Abu Dhabi Bank PJSC certificates.
  8. Entrust completed revocation for Fidelity Investments certificates; all certificates were revoked.
  9. Mozilla scheduled closure of the incident.
Thread Activity
  1. Entrust representative — Bruce Morton created the incident report attachment, describing the incorrect-jurisdiction EV TLS incident and explaining that revocation for some certificates was delayed due to blackout periods.
  2. Entrust representative — Morton reported that Prudential Financial certificates were revoked on 2 December 2022, ING Groep completed revoking on 4 December 2022, Munich Re Group completed revoking on 16 December 2022, and Azimut Holding certificates were revoked on 17 December 2022.
  3. Sectigo — Katerbarg asked for clarification of Entrust’s criteria for granting subscriber extensions, including what made circumstances exceptional, how key-compromise scenarios would be handled, and why the incident was not opened within the 5-day revocation window.
  4. Entrust representative — Morton explained that Entrust accepted blackout-period extension requests due to concern about harm to relying parties, stated it would not extend for key compromise, and clarified that the plan was to revoke within 5 days but to open a delayed revocation incident if not.
  5. Entrust representative — Morton reported that Experian certificates were revoked on 15 January 2023.
  6. Entrust representative — Morton reported that First Abu Dhabi Bank PJSC certificates were revoked on 6 February 2023.
  7. Google representative — Chris Clements requested an update to the incident report items covering root cause and remaining next steps.
  8. Entrust representative — Morton stated that Fidelity Investments certificate revocation was completed on 15 March 2023 and that all certificates have been revoked.
  9. Mozilla representative — Mozilla asked for updates to the incident report items #6 and #7, and Entrust responded with details about why revocation could not occur within 5 days and the mitigation steps being taken.
  10. Mozilla representative — Mozilla stated the incident could be closed and scheduled closure for 19-Apr-2023.
Participants
Entrust representative Sectigo Google representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1943528 RESOLVED Delayed Revocation Opened 2025-01-24 · Closed 2025-02-19 · 98% similar
Entrust: delayed revocation
#1636339 RESOLVED Delayed Revocation Opened 2020-05-08 · Closed 2023-02-22 · 98% similar
Entrust: Failure to revoke a certificate
#1886532 RESOLVED Delayed Revocation Opened 2024-03-20 · Closed 2025-02-21 · 97% similar
Entrust: Delayed revocation of EV TLS certificates with missing cPSuri
#1885754 RESOLVED Delayed Revocation Opened 2024-03-16 · Closed 2024-09-13 · 96% similar
Entrust: CPR was not responded to in 24 hours
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 96% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1898848 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2025-02-21 · 96% similar
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
#1910237 RESOLVED Delayed Revocation Closure Request Opened 2024-07-27 · Closed 2025-05-13 · 96% similar
Entrust: Delayed Revocation for S/MIME certificates
#1898847 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2024-08-15 · 88% similar
Entrust: Delayed reporting of Jurisdiction issue in some EV TLS & Code Signing certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action