← Entrust cases
Bugzilla #1879602 Certificate Problem Report

Entrust: OCSP response signed with SHA-1

RESOLVED FIXED Entrust
AI Summary

Entrust identified that two of its root CA OCSP responders were incorrectly signing responses using SHA-1 instead of the required SHA-256. This issue was discovered through monitoring with OCSP Watch. Upon confirmation, Entrust quickly scheduled a fix, which was implemented on February 6, 2024. The root cause was traced back to a failure in updating the online OCSP responders to comply with the SHA-1 sunset date. Entrust has since updated its monitoring procedures and operational protocols to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:35 UTC Confidence: 0.95
Chronology
  1. Operations reviewed OCSP Watch and identified the SHA-1 signing issue.
  2. Authorization to fix the issue was confirmed.
  3. The fix was applied to production.
  4. Monitoring was updated to ensure compliance.
  5. All actions were completed, and the incident was requested to be closed.
Participants
Bruce Morton Aaron Mathew Hodson Amir Aamidi Clint Wilson
Similar Local Cases
#1886467 RESOLVED Certificate Problem Report Opened 2024-03-20 · Closed 2024-06-28 · 65% similar
Entrust: clientAuth TLS Certificates without serverAuth EKU
#1890685 RESOLVED Certificate Problem Report Opened 2024-04-09 · Closed 2025-02-21 · 63% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1766525 RESOLVED Certificate Problem Report Opened 2022-04-26 · Closed 2023-02-22 · 63% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1448986 RESOLVED Certificate Problem Report Opened 2018-03-26 · Closed 2023-02-22 · 60% similar
Entrust: IP Address in dNSName form
#1636339 RESOLVED Certificate Problem Report Opened 2020-05-08 · Closed 2023-02-22 · 60% similar
Entrust: Failure to revoke a certificate
#1667448 RESOLVED Certificate Problem Report Opened 2020-09-25 · Closed 2023-02-22 · 60% similar
Entrust: Incorrect keyUsage for ECC certificate
#1731887 RESOLVED Certificate Problem Report Opened 2021-09-21 · Closed 2023-02-22 · 60% similar
Entrust: Test Website Certificates Expired
#1635096 RESOLVED Certificate Problem Report Opened 2020-05-04 · Closed 2023-02-22 · 59% similar
Entrust: Printable String Constraint Failure

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action