Entrust delayed revocation of clientAuth TLS certificates without serverAuth EKU
Entrust opened this bug as a preliminary incident report about delayed revocation of clientAuth TLS certificates that lacked the serverAuth EKU, which were already reported in bug 1886467. Entrust said the affected certificates should have been revoked within 5 days after the incident was known, and that this bug was specifically about the revocation delay rather than the original misissuance. Over the course of the thread, Entrust posted weekly progress updates, later added a per-customer breakdown for the remaining certificates, and explained that some subscribers needed more time to test replacement certificates or complete internal change-control steps. Mozilla participants repeatedly asked for clearer separation of revoked versus expired certificates and for more transparency about subscriber-by-subscriber remediation. Entrust later said it would include that distinction in future updates and pointed to a detailed report with remediation action items. Entrust ultimately reported that all 1,176 affected certificates had been revoked or expired by 2024-05-30, and the bug was resolved fixed.
- Entrust began contacting impacted customers and asked them to replace and revoke their id-kp-clientAuth-only TLS certificates.
- Entrust opened a preliminary incident report focused on delayed revocation for the affected certificates.
- Entrust published a per-customer breakdown for the remaining delayed revocations, including estimated completion dates.
- Entrust reported that all 1,176 affected certificates had been revoked or expired.
- Entrust representative — Entrust said the incident involved clientAuth TLS certificates issued without serverAuth EKU and that this bug covered delayed revocation only.
- Entrust representative — Entrust said it would add a breakdown of affected subscribers and noted that one customer held the large majority of impacted certificates.
- Entrust representative — Entrust listed the remaining customer accounts and gave reasons and estimated completion dates for each.
- Entrust representative — Entrust clarified the revoked-versus-expired counts and said it would include that distinction in future updates.
- Entrust representative — Entrust said it had implemented PKIlint for post-linting, was offering automation options, and was considering further tooling and process improvements.
- Entrust representative — Entrust reported that all 1,176 certificates and all 114 customer accounts had been fully remediated.
- Entrust representative — Entrust confirmed that the statements about subscriber responses and a presumption of denial also applied to this bug and pointed to a detailed remediation report.