← Entrust cases
Bugzilla #1889217 Incident

Entrust: CRL non-conformance with the TLS BRs

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust disclosed a compliance issue regarding two of its Certificate Revocation Lists (CRLs) that contained a revoked certificates field without any revoked certificates, violating RFC 5280 and TLS BRs. The issue was detected through the use of linting software and manual investigation. Entrust investigated the problem, identifying a bug in their CRL generation system. They updated the software to ensure compliance and issued new CRLs. An incident report detailing the root cause and corrective actions was prepared and shared, confirming no security impact from the issue.

Model: gpt-4o-mini Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:56 UTC Confidence: 0.90 17 comments
Chronology
  1. Entrust disclosed a CRL compliance issue to the CCADB.
  2. Entrust updated its CRL generation software and published compliant CRLs.
  3. Entrust submitted an incident report detailing the issue and corrective actions.
Thread Activity
  1. Google representative — Reported CRL compliance issue regarding revoked certificates field.
  2. Entrust representative — Acknowledged the issue and stated that an investigation was underway.
  3. Entrust representative — Confirmed the issue was due to a bug in the CRL generation system and that updates were made.
  4. Entrust representative — Shared the incident report detailing the findings and corrective actions.
  5. Mozilla representative — Closed the bug but noted it will remain on the list of Entrust compliance issues.
Participants
Community commenter
Similar Local Cases
#1888689 RESOLVED Ca Certificate Compliance Incident Opened 2024-03-29 · Closed 2024-10-02 · 84% similar
Asseco DS / Certum: CRL non-conformance with the TLS BRs
#1737057 RESOLVED Incident Opened 2021-10-21 · Closed 2023-02-22 · 79% similar
Entrust: CRLs and OCSP responses not issued as specified in the CPS
#1890123 RESOLVED Incident Opened 2024-04-06 · Closed 2024-08-13 · 78% similar
Entrust: Failed to provide a preliminary incident report according to TLS BR 4.9.5
#1731887 RESOLVED Incident Opened 2021-09-21 · Closed 2023-02-22 · 78% similar
Entrust: Test Website Certificates Expired
#1551363 RESOLVED Incident Opened 2019-05-14 · Closed 2023-02-22 · 63% similar
DigiCert: "Some-State" in stateOrProvinceName
#1690807 RESOLVED Incident Self Reported Incident Opened 2021-02-04 · Closed 2023-02-22 · 62% similar
GlobalSign: RSA-1024 leaf certificate issued after 2013-12-31
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 62% similar
HARICA: 3 EV TLS Certificates without L or ST
#1664328 RESOLVED Incident Self Reported Incident Opened 2020-09-10 · Closed 2023-02-22 · 62% similar
GlobalSign: SHA-256 hash algorithm used with ECC P-384 key

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action