← Entrust cases
Bugzilla #1890685 Revocation Issue Certificate Misissuance

Entrust revised its position on whether March 18–21 EV TLS certificates were mis-issued and whether revocation was required

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust opened this case to report on a subset of EV TLS certificates issued between 2024-03-18 21:33:53 UTC and 2024-03-21 16:34:44 UTC. The initial report said the certificates were mis-issued because they were issued before the CPS update was published, and Entrust said it would not revoke them due to exceptional circumstances. After further review with internal legal counsel and external experts, Entrust later said it had likely mischaracterized the certificates as mis-issued and concluded there was no need to revoke them. Entrust also stated that the CPS, read as a whole, required compliance with the EV Guidelines and that this overrode the inconsistent CPS wording. The thread includes repeated criticism from Mozilla and community members about the non-revocation decision, the adequacy of the analysis, and whether the follow-up actions addressed delayed revocation. Entrust later said all action items were closed and that it would continue to monitor the bug.

Model: gpt-5.4-mini Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:56 UTC Confidence: 0.93 103 comments
Chronology
  1. Entrust began issuing EV TLS certificates with the corrected profile after updating the certificate profile.
  2. Entrust uploaded the updated CPS to its website.
  3. Entrust stated its intent not to revoke the affected March 18–21 certificates.
  4. Entrust said it had likely mischaracterized the March 18–21 certificates as mis-issued after review with legal counsel and external experts.
  5. Entrust filed a revised analysis saying there was no mis-issuance and no need to revoke the March 18–21 certificates.
Thread Activity
  1. Entrust representative — Entrust filed an incident report saying it would not revoke the affected certificates because it believed revocation would not benefit the Web PKI.
  2. Community commenter — Questioned Entrust’s claim that there was no impact from failing to revoke and challenged the justification for non-revocation.
  3. Community commenter — Said the impact section should describe the size and nature of the incident rather than argue that the incident was not serious.
  4. Entrust representative — Explained that the affected certificates were mostly re-issued certificates from the earlier cPSuri incident and said revocation would cause confusion.
  5. Google representative — Raised concerns that Entrust’s response was inconsistent with its commitments and asked whether affected subscribers had been notified.
  6. Entrust representative — Said subscribers had been notified of the CPS error and that Entrust had not told them to expect revocation.
  7. Entrust representative — Said all action items were closed and that Entrust had no updates that week.
  8. Entrust representative — Updated the action list to add support for ACME Renewal Information (ARI) as a mitigation item.
  9. Entrust representative — Said questions would be addressed in a June 7 report to Mozilla and the community.
  10. Entrust representative — Said Entrust would work to answer all questions per CCADB requirements.
  11. Entrust representative — Posted a revised report stating Entrust now believed there was no mis-issuance and no need to revoke the March 18–21 certificates.
  12. Entrust representative — Said Entrust’s original non-revocation analysis was not supported and that the company stood by the revised analysis.
  13. Community commenter — Objected to the revised claim that the case was not a mis-issuance.
Participants
Entrust representative Community commenter Google representative Namepros representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1886467 RESOLVED Certificate Misissuance Opened 2024-03-20 · Closed 2024-06-28 · 100% similar
Entrust: clientAuth TLS Certificates without serverAuth EKU
#1887753 RESOLVED Certificate Misissuance Audit Finding Opened 2024-03-25 · Closed 2024-07-12 · 100% similar
Entrust: Delay in Updating CPS
#1888714 RESOLVED Certificate Misissuance Opened 2024-03-29 · Closed 2024-07-11 · 100% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1890896 RESOLVED Ca Documents Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 100% similar
Entrust: CPS typographical (text placement) error
#1712106 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2021-05-20 · Closed 2023-02-22 · 96% similar
Entrust: Invalid localityName
#1914065 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-08-20 · Closed 2025-02-28 · 95% similar
Entrust: S/MIME certificates lacking OU verification
#1685370 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2021-01-06 · Closed 2023-02-22 · 95% similar
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 95% similar
Entrust: EV TLS Certificate incorrect jurisdiction

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action