Entrust revised its position on whether March 18–21 EV TLS certificates were mis-issued and whether revocation was required
Entrust opened this case to report on a subset of EV TLS certificates issued between 2024-03-18 21:33:53 UTC and 2024-03-21 16:34:44 UTC. The initial report said the certificates were mis-issued because they were issued before the CPS update was published, and Entrust said it would not revoke them due to exceptional circumstances. After further review with internal legal counsel and external experts, Entrust later said it had likely mischaracterized the certificates as mis-issued and concluded there was no need to revoke them. Entrust also stated that the CPS, read as a whole, required compliance with the EV Guidelines and that this overrode the inconsistent CPS wording. The thread includes repeated criticism from Mozilla and community members about the non-revocation decision, the adequacy of the analysis, and whether the follow-up actions addressed delayed revocation. Entrust later said all action items were closed and that it would continue to monitor the bug.
- Entrust began issuing EV TLS certificates with the corrected profile after updating the certificate profile.
- Entrust uploaded the updated CPS to its website.
- Entrust stated its intent not to revoke the affected March 18–21 certificates.
- Entrust said it had likely mischaracterized the March 18–21 certificates as mis-issued after review with legal counsel and external experts.
- Entrust filed a revised analysis saying there was no mis-issuance and no need to revoke the March 18–21 certificates.
- Entrust representative — Entrust filed an incident report saying it would not revoke the affected certificates because it believed revocation would not benefit the Web PKI.
- Community commenter — Questioned Entrust’s claim that there was no impact from failing to revoke and challenged the justification for non-revocation.
- Community commenter — Said the impact section should describe the size and nature of the incident rather than argue that the incident was not serious.
- Entrust representative — Explained that the affected certificates were mostly re-issued certificates from the earlier cPSuri incident and said revocation would cause confusion.
- Google representative — Raised concerns that Entrust’s response was inconsistent with its commitments and asked whether affected subscribers had been notified.
- Entrust representative — Said subscribers had been notified of the CPS error and that Entrust had not told them to expect revocation.
- Entrust representative — Said all action items were closed and that Entrust had no updates that week.
- Entrust representative — Updated the action list to add support for ACME Renewal Information (ARI) as a mitigation item.
- Entrust representative — Said questions would be addressed in a June 7 report to Mozilla and the community.
- Entrust representative — Said Entrust would work to answer all questions per CCADB requirements.
- Entrust representative — Posted a revised report stating Entrust now believed there was no mis-issuance and no need to revoke the March 18–21 certificates.
- Entrust representative — Said Entrust’s original non-revocation analysis was not supported and that the company stood by the revised analysis.
- Community commenter — Objected to the revised claim that the case was not a mis-issuance.