Entrust delayed revocation of EV TLS certificates with missing cPSuri
Entrust reported a delayed revocation incident involving EV TLS certificates that were missing a cPSuri, with the delayed revocation case tracked separately from the original misissuance report in bug 1883843. Entrust said the affected certificates should have been revoked within 5 days after the incident was known, and that this bug focused only on the revocation delay. The thread documents weekly progress updates as Entrust worked with subscribers to replace and revoke the affected certificates, including explanations that some revocations were delayed because subscribers reported business disruption, technical challenges, or impacts to the web ecosystem. Entrust also described its process for contacting subscribers by email, phone, video calls, and support tickets, and said it used a product compliance leader and later a cross-functional senior leadership team to decide on delayed revocation requests. The company later said it would provide future updates with a revoked-versus-expired distinction and that it had created attachments with per-customer breakdowns. The bug was resolved as FIXED, and the final thread comments state that all outstanding certificates were revoked.
- Original EV misissuance was confirmed in bug 1883843.
- Entrust stopped issuing the misissued certificates and fixed the EV certificate profile.
- Entrust said affected certificates were required to be revoked as soon as possible.
- The last outstanding affected certificates were revoked.
- Entrust representative — Entrust opened the incident report and said the bug focused on delayed revocation for the EV TLS certificates missing cPSuri.
- Entrust representative — Entrust reported progress revoking and reissuing 26,668 affected EV certificates across 944 customer accounts.
- Mozilla representative — Mozilla said it was not considering distrust at that time and wanted Entrust to report and remediate the deficiencies.
- Entrust representative — Entrust explained how it communicated with subscribers, how delayed revocation decisions were made, and that it had not always recorded the rationale effectively early in the response.
- Entrust representative — Entrust said it had no examples of revoking without subscriber response and that all subscribers had responded by the end of the effort.
- Entrust representative — Entrust reported 26,659 of 26,668 certificates revoked or expired and listed the remaining certificates with due dates.
- Community commenter — A commenter confirmed that all outstanding certificates had been revoked and noted the incident took 95 days to resolve from the misissuance date.
- Mozilla representative — Mozilla requested a closure summary.