Entrust: OCSP response signed with SHA-1
Entrust identified that two of its root CA OCSP responders were signing responses using the SHA-1 algorithm, which is non-compliant with the CA/Browser Forum's requirements. This issue was discovered on February 3, 2024, through monitoring by OCSP Watch. Entrust promptly scheduled a fix, which was implemented on February 6, 2024, to ensure that OCSP responses would be signed with SHA-256 instead. The root cause was attributed to a failure to update the online OCSP responders in line with the SHA-1 sunset date. Entrust has since updated its operational procedures to prevent similar issues in the future. The incident has been resolved and all action items completed.
- Operations reviewed OCSP Watch and discovered SHA-1 signing issue.
- Fix applied to production to switch OCSP signing to SHA-256.
- Entrust representative — Summary of the incident and actions taken was provided.
- Entrust representative — Monitoring using OCSP Watch was added and action items completed.
- Entrust representative — All actions are complete. Requesting to close this incident.