← Entrust cases
Bugzilla #1890896 Ca Documents Certificate Misissuance

Entrust CPS typographical error affecting OV TLS certificate profiles

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust reported that a CPS update accidentally added an EV-only policyQualifier requirement to the OV SSL certificate profile in CPS version 3.18. Entrust said the OV certificates themselves were issued correctly, but the CPS text was wrong, and it treated the affected certificates as mis-issued under CCADB policy. The company corrected the CPS in version 3.20 and later added errata to versions 3.18 and 3.19. Entrust also said it would not revoke the 6,008 affected OV TLS certificates and referenced a separate bug for that revocation decision. The thread then focused on subscriber notification, the format and visibility of the errata, and whether the action items were properly categorized. Entrust later stated that all action items were completed and requested closure of the incident.

Model: gpt-5.4-mini Generated: 2026-06-13 21:38 UTC Revised: 2026-06-16 18:56 UTC Confidence: 0.96 48 comments
Chronology
  1. Entrust published CPS version 3.18 with an OV profile text error adding an EV-only policyQualifier requirement.
  2. Entrust discovered the CPS typographical error and published CPS version 3.20 correcting it.
  3. Entrust opened the Mozilla bug and described the incident as affecting 6,008 OV TLS certificates.
  4. Entrust informed subscribers of the CPS changes.
  5. Entrust said all action items had been completed and requested closure of the incident.
Thread Activity
  1. Entrust representative — Entrust filed the bug and attached the incident report describing the CPS typo and its impact.
  2. Entrust representative — Entrust explained that CPS 3.18 mistakenly applied an EV-only requirement to the OV SSL profile and said it would not revoke the affected certificates.
  3. Entrust representative — Entrust said subscribers were informed of the CPS changes.
  4. Community commenter — A commenter asked for clarification on revocation, the status of affected certificates, and the basis for any exception from revocation.
  5. Entrust representative — Entrust said it had not started or requested revocation for this incident, would not revoke the certificates, and had spoken with some root programs only about the delayed CPS publication.
  6. Entrust representative — Entrust explained that the errata was added as a PDF comment and that the red strikethrough was intended to show the incorrect text.
  7. Entrust representative — Entrust said it was not relying on any authority for the non-revocation position and had opened bug 1890898 to address that issue.
  8. Entrust representative — Entrust clarified that the CPS was updated with an erratum in red so readers would see the corrected information.
  9. Entrust representative — Entrust updated the action table and marked the subscriber notice and errata items as done.
  10. Entrust representative — Entrust said all action items were complete and requested that the incident be closed.
Participants
Entrust representative Mozilla representative DigiCert Community commenter Google representative Apple representative Namepros representative Sectigo Seferiadis representative Trash representative HARICA
Related Bugzilla IDs Mentioned
Similar Local Cases
#1886467 RESOLVED Certificate Misissuance Opened 2024-03-20 · Closed 2024-06-28 · 100% similar
Entrust: clientAuth TLS Certificates without serverAuth EKU
#1887753 RESOLVED Certificate Misissuance Audit Finding Opened 2024-03-25 · Closed 2024-07-12 · 100% similar
Entrust: Delay in Updating CPS
#1888714 RESOLVED Certificate Misissuance Opened 2024-03-29 · Closed 2024-07-11 · 100% similar
Entrust: EV Certificate missing Issuer’s EV Policy OID
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 100% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1894111 RESOLVED Ca Documents Self Reported Incident Opened 2024-04-29 · Closed 2025-01-22 · 100% similar
Entrust: Not updating CPR Problem Reporting Mechanism fields in CCADB
#1906467 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 100% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1906470 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-07-05 · Closed 2025-05-13 · 100% similar
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
#1744827 RESOLVED Certificate Misissuance Delayed Revocation Opened 2021-12-07 · Closed 2024-03-08 · 100% similar
Entrust: SSL Certificates issued with Un-verified IP Addresses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action