← Entrust cases
Bugzilla #1886467 Certificate Misissuance

Entrust: clientAuth TLS Certificates without serverAuth EKU

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust identified a compliance issue involving 15 EV certificates that were issued with the Extended Key Usage (EKU) attribute set to `id-kp-clientAuth` but lacking the required `id-kp-serverAuth` attribute. This issue was discovered during a review related to another incident. Entrust promptly halted the issuance of such certificates and began contacting affected customers to replace and revoke the non-compliant certificates. The incident was documented, and action items were established to improve compliance checks and prevent future occurrences. The issue was resolved, and all actions have been completed as of June 2024.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.90 20 comments
Chronology
  1. Entrust confirmed a compliance issue with clientAuth TLS certificates.
  2. Entrust requested closure of the incident after completing all actions.
Thread Activity
  1. Entrust representative — Created incident report detailing the compliance issue with clientAuth certificates.
  2. Entrust representative — Updated action item regarding fixing TLS BR EKU checking in zlint to done.
  3. Entrust representative — Requested closure of the incident after all actions were completed.
Participants
Entrust representative Google representative Community commenter HARICA Apple representative
External References
Similar Local Cases
#1887753 RESOLVED Certificate Misissuance Audit Finding Opened 2024-03-25 · Closed 2024-07-12 · 100% similar
Entrust: Delay in Updating CPS
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 100% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1890896 RESOLVED Ca Documents Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 100% similar
Entrust: CPS typographical (text placement) error
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 100% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 100% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 99% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1888714 RESOLVED Certificate Misissuance Opened 2024-03-29 · Closed 2024-07-11 · 96% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1914065 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-08-20 · Closed 2025-02-28 · 91% similar
Entrust: S/MIME certificates lacking OU verification

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action