Entrust EV TLS certificates missing cPSuri in policy qualifiers
Entrust reported that its EV TLS certificates were missing the required certificatePolicies policy qualifier cPSuri after certificate profile changes made for Ballot SC-62v2. The issue was first raised by Ryan Dickson, and Entrust initially confirmed the mis-issuance, then argued it was caused by a mismatch between the TLS Baseline Requirements and the EV Guidelines. Community members and Mozilla asked Entrust to stop issuance and handle revocation separately in a delayed revocation bug. Entrust later said it had stopped issuing the mis-issued certificates, fixed the EV certificate profile, and would revoke impacted certificates. Entrust also provided updated affected-certificate lists, including a corrected list of 26,653 affected certificates, and said all action items in the bug were completed. The bug was later requested to be closed, with Mozilla noting that procedure-improvement items should be tracked separately.
- Entrust deployed EV certificate profile changes and mis-issuance began.
- An external report alleged EV TLS certificates were missing the cPSuri policy qualifier.
- Entrust confirmed the mis-issuance and requested a report of all impacted EV TLS certificates.
- Entrust stopped issuing the mis-issued certificates and fixed the EV certificate profile.
- Entrust provided an affected-certificate list and later corrected it.
- Entrust filed a separate delayed revocation incident and a separate incident for clientAuth-only certificates.
- Entrust said all action items in this bug were completed and requested closure.
- Entrust representative — Entrust opened the incident report, described the missing cPSuri problem, and said the mis-issuance affected all EV TLS certificates issued since the SC-62v2 changes.
- Mozilla representative — Mozilla said Entrust should stop issuance, fix the EV profile, and file a separate delayed revocation bug.
- Google representative — Chrome Root Program feedback said the initial report did not meet expectations and asked for better incident reporting and remediation.
- Entrust representative — Entrust said it had stopped issuing the mis-issued certificates, fixed the EV profile, and would advise impacted customers that the certificates would be revoked.
- Entrust representative — Entrust attached a list of 24,246 affected certificates, then corrected it to 26,641 and later 26,653 affected certificates.
- Entrust representative — Entrust said the 15 NULL entries were clientAuth-only certificates and later corrected that they were impacted and would also be revoked, referencing bug 1886467.
- Entrust representative — Entrust published an updated incident report saying 26,668 EV certificates were impacted and that issuance had been corrected on 2024-03-18.
- Mozilla representative — Mozilla said procedure-improvement action items should be added to bug 1901270 before closure.