← Entrust cases
Bugzilla #1886532 Delayed Revocation

Entrust: Delayed revocation of EV TLS certificates with missing cPSuri

RESOLVED FIXED Entrust
AI Summary

Entrust faced a significant incident involving the delayed revocation of EV TLS certificates due to missing cPSuri. The revocation process was complicated by the need to coordinate with multiple teams and external companies, leading to extended timelines for certificate replacement. Entrust acknowledged that the delays were not in line with the expected standards and committed to improving their processes to ensure compliance with the Baseline Requirements in the future. The incident has raised concerns about the handling of critical infrastructure certificates and the necessity for stricter adherence to revocation timelines.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Confidence: 0.90
Chronology
  1. Publication of the original preliminary incident report.
  2. Initial briefing support teams and stopping the issuance of mis-issued certificates.
  3. Requested impacted customers to replace their certificates.
  4. All affected certificates were revoked.
Participants
paul.vanbrouwershaven@entrust.com bwilson@mozilla.com jrmoir@protonmail.com rdaurne77@gmail.com tim.callan@sectigo.com martijn.katerbarg@sectigo.com Zacharias.bjorngren@gmail.com
External References
Similar Local Cases
#1898848 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2025-02-21 · 77% similar
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
#1947691 RESOLVED Delayed Revocation Opened 2025-02-12 · Closed 2025-08-19 · 58% similar
NETLOCK: Bug 1891331 replacement - delayed revocation -
#1903066 RESOLVED Delayed Revocation Opened 2024-06-17 · Closed 2025-02-12 · 58% similar
Chunghwa Telecom: Delayed Revocation with Controversial Extension (2.5.29.9, SubjectDirectoryAttributes)
#1892419 RESOLVED Delayed Revocation Opened 2024-04-19 · Closed 2025-02-12 · 57% similar
Chunghwa Telecom: Delayed Revocation Due to GTLSCA EKU Misissuance
#1651481 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 52% similar
Entrust: Late Revocation due to SHA-256 hash algorithm
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 51% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1658794 RESOLVED Delayed Revocation Opened 2020-08-12 · Closed 2023-02-22 · 50% similar
Entrust: Late Revocation for Invalid State/Province Issue
#1804753 RESOLVED Delayed Revocation Opened 2022-12-08 · Closed 2023-04-19 · 50% similar
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action