Entrust: clientAuth TLS Certificates without serverAuth EKU
Entrust identified a compliance issue involving 15 EV certificates that were issued with the Extended Key Usage (EKU) attribute set to `id-kp-clientAuth` but lacking the required `id-kp-serverAuth` attribute. This issue was discovered during a review related to another incident. Entrust promptly halted the issuance of such certificates and began contacting affected customers to replace and revoke the non-compliant certificates. The incident was documented, and action items were established to improve compliance checks and prevent future occurrences. The issue was resolved, and all actions have been completed as of June 2024.
- Entrust confirmed a compliance issue with clientAuth TLS certificates.
- Entrust requested closure of the incident after completing all actions.
- Entrust representative — Created incident report detailing the compliance issue with clientAuth certificates.
- Entrust representative — Updated action item regarding fixing TLS BR EKU checking in zlint to done.
- Entrust representative — Requested closure of the incident after all actions were completed.