← Entrust cases
Bugzilla #1887705 Delayed Revocation

Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU

RESOLVED FIXED Entrust
AI Summary

Entrust experienced a significant delay in revoking clientAuth TLS certificates that lacked the serverAuth EKU. The issue arose after the CA was made aware of the misissuance, with a commitment to revoke affected certificates within five days. However, various challenges, including customer dependencies and inadequate automation, led to a prolonged revocation timeline. As of June 28, 2024, all affected certificates have been revoked, and Entrust has committed to improving their processes to prevent future delays.

Model: gpt-4o-mini Generated: 2026-06-13 21:37 UTC Confidence: 0.95
Chronology
  1. Entrust began contacting impacted customers regarding certificate replacement.
  2. All outstanding certificates were successfully revoked.
  3. Entrust confirmed that all certificates have been revoked.
Participants
Paul van Brouwershaven Bruce Morton Ngook Kong Mike Shaver Wayne Dimitris Zacharopoulos Tim Callan R. Daurne
External References
Similar Local Cases
#1887110 RESOLVED Delayed Revocation Opened 2024-03-22 · Closed 2025-02-14 · 64% similar
Microsec: Delayed revocation of the misissued certificates
#1651481 RESOLVED Delayed Revocation Opened 2020-07-08 · Closed 2023-02-22 · 60% similar
Entrust: Late Revocation due to SHA-256 hash algorithm
#1804753 RESOLVED Delayed Revocation Opened 2022-12-08 · Closed 2023-04-19 · 59% similar
Entrust: Delayed Revocation for EV TLS Certificate incorrect jurisdiction
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 58% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1877388 RESOLVED Delayed Revocation Opened 2024-01-30 · Closed 2025-03-14 · 55% similar
Telekom Security: Revocation delay for TLS certificates with basicConstraints not marked as critical
#1898848 RESOLVED Delayed Revocation Opened 2024-05-25 · Closed 2025-02-21 · 54% similar
Entrust: Delayed revocation of certificates affected by Jurisdiction issue in some EV TLS & Code Signing certificates
#1658794 RESOLVED Delayed Revocation Opened 2020-08-12 · Closed 2023-02-22 · 52% similar
Entrust: Late Revocation for Invalid State/Province Issue
#1888882 RESOLVED Delayed Revocation Opened 2024-04-01 · Closed 2025-03-27 · 52% similar
CFCA: Delayed revocation of TLS certificates(basicConstraints extension not marked as critical)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action