← Entrust cases
Bugzilla #1883843 Certificate Misissuance

Entrust EV TLS certificates missing cPSuri in policy qualifiers

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust reported that its EV TLS certificates were missing the required certificatePolicies policy qualifier cPSuri after certificate profile changes made for Ballot SC-62v2. The issue was first raised by Ryan Dickson, and Entrust initially confirmed the mis-issuance, then argued it was caused by a mismatch between the TLS Baseline Requirements and the EV Guidelines. Community members and Mozilla asked Entrust to stop issuance and handle revocation separately in a delayed revocation bug. Entrust later said it had stopped issuing the mis-issued certificates, fixed the EV certificate profile, and would revoke impacted certificates. Entrust also provided updated affected-certificate lists, including a corrected list of 26,653 affected certificates, and said all action items in the bug were completed. The bug was later requested to be closed, with Mozilla noting that procedure-improvement items should be tracked separately.

Model: gpt-5.4-mini Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 17:28 UTC Confidence: 0.97 71 comments
Chronology
  1. Entrust deployed EV certificate profile changes and mis-issuance began.
  2. An external report alleged EV TLS certificates were missing the cPSuri policy qualifier.
  3. Entrust confirmed the mis-issuance and requested a report of all impacted EV TLS certificates.
  4. Entrust stopped issuing the mis-issued certificates and fixed the EV certificate profile.
  5. Entrust provided an affected-certificate list and later corrected it.
  6. Entrust filed a separate delayed revocation incident and a separate incident for clientAuth-only certificates.
  7. Entrust said all action items in this bug were completed and requested closure.
Thread Activity
  1. Entrust representative — Entrust opened the incident report, described the missing cPSuri problem, and said the mis-issuance affected all EV TLS certificates issued since the SC-62v2 changes.
  2. Mozilla representative — Mozilla said Entrust should stop issuance, fix the EV profile, and file a separate delayed revocation bug.
  3. Google representative — Chrome Root Program feedback said the initial report did not meet expectations and asked for better incident reporting and remediation.
  4. Entrust representative — Entrust said it had stopped issuing the mis-issued certificates, fixed the EV profile, and would advise impacted customers that the certificates would be revoked.
  5. Entrust representative — Entrust attached a list of 24,246 affected certificates, then corrected it to 26,641 and later 26,653 affected certificates.
  6. Entrust representative — Entrust said the 15 NULL entries were clientAuth-only certificates and later corrected that they were impacted and would also be revoked, referencing bug 1886467.
  7. Entrust representative — Entrust published an updated incident report saying 26,668 EV certificates were impacted and that issuance had been corrected on 2024-03-18.
  8. Mozilla representative — Mozilla said procedure-improvement action items should be added to bug 1901270 before closure.
Participants
Entrust representative Community commenter Internet Security Research Group Namepros representative Daknob representative Mozilla representative Google representative Sectigo
Related Bugzilla IDs Mentioned
Similar Local Cases
#1890898 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 100% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 100% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1918380 RESOLVED Certificate Misissuance Opened 2024-09-12 · Closed 2024-11-06 · 98% similar
Entrust: Business Entity not permitted in CPS
#1667448 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 97% similar
Entrust: Incorrect keyUsage for ECC certificate
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 97% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1567659 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 88% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 87% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1890896 RESOLVED Ca Documents Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 87% similar
Entrust: CPS typographical (text placement) error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action