← Entrust cases
Bugzilla #1886467 Certificate Problem Report

Entrust: clientAuth TLS Certificates without serverAuth EKU

RESOLVED FIXED Entrust
AI Summary

Entrust identified a compliance issue involving 15 EV certificates that were issued with the Extended Key Usage (EKU) attribute set to `id-kp-clientAuth` but lacking the required `id-kp-serverAuth` attribute. This incident affects a total of 1176 TLS certificates, which, while non-compliant, do not pose a security risk. The issue arose from a misunderstanding of the updated TLS Baseline Requirements, which now mandate the presence of the `id-kp-serverAuth` EKU. Entrust has since halted the issuance of such certificates and is working on corrective actions.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Confidence: 0.90
Chronology
  1. Suspicion of potential miss-issuance confirmed; incident response triggered.
  2. Issuance of non-compliant certificates stopped.
  3. Impacted customers notified to replace and revoke their certificates.
  4. All actions completed; closure of incident requested.
Participants
Paul van Brouwershaven Ryan Dickson Mathew Hodson Bruce Morton Dimitris Zacharopoulos
Similar Local Cases
#1889217 RESOLVED Certificate Problem Report Opened 2024-04-02 · Closed 2024-07-01 · 70% similar
Entrust: CRL non-conformance with the TLS BRs
#1888714 RESOLVED Certificate Problem Report Opened 2024-03-29 · Closed 2024-07-11 · 69% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1744827 RESOLVED Certificate Problem Report Opened 2021-12-07 · Closed 2024-03-08 · 67% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses
#1890685 RESOLVED Certificate Problem Report Opened 2024-04-09 · Closed 2025-02-21 · 65% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1879602 RESOLVED Certificate Problem Report Opened 2024-02-09 · Closed 2024-07-19 · 65% similar
Entrust: OCSP response signed with SHA-1
#1943528 RESOLVED Certificate Problem Report Opened 2025-01-24 · Closed 2025-02-19 · 63% similar
Entrust: delayed revocation
#1931886 RESOLVED Certificate Problem Report Opened 2024-11-18 · Closed 2025-02-12 · 59% similar
Entrust: CRL missing revocation reasonCode
#1731887 RESOLVED Certificate Problem Report Opened 2021-09-21 · Closed 2023-02-22 · 59% similar
Entrust: Test Website Certificates Expired

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action