Entrust CPS typographical error affecting OV TLS certificate profiles
Entrust reported that a CPS update accidentally added an EV-only policyQualifier requirement to the OV SSL certificate profile in CPS version 3.18. Entrust said the OV certificates themselves were issued correctly, but the CPS text was wrong, and it treated the affected certificates as mis-issued under CCADB policy. The company corrected the CPS in version 3.20 and later added errata to versions 3.18 and 3.19. Entrust also said it would not revoke the 6,008 affected OV TLS certificates and referenced a separate bug for that revocation decision. The thread then focused on subscriber notification, the format and visibility of the errata, and whether the action items were properly categorized. Entrust later stated that all action items were completed and requested closure of the incident.
- Entrust published CPS version 3.18 with an OV profile text error adding an EV-only policyQualifier requirement.
- Entrust discovered the CPS typographical error and published CPS version 3.20 correcting it.
- Entrust opened the Mozilla bug and described the incident as affecting 6,008 OV TLS certificates.
- Entrust informed subscribers of the CPS changes.
- Entrust said all action items had been completed and requested closure of the incident.
- Entrust representative — Entrust filed the bug and attached the incident report describing the CPS typo and its impact.
- Entrust representative — Entrust explained that CPS 3.18 mistakenly applied an EV-only requirement to the OV SSL profile and said it would not revoke the affected certificates.
- Entrust representative — Entrust said subscribers were informed of the CPS changes.
- Community commenter — A commenter asked for clarification on revocation, the status of affected certificates, and the basis for any exception from revocation.
- Entrust representative — Entrust said it had not started or requested revocation for this incident, would not revoke the certificates, and had spoken with some root programs only about the delayed CPS publication.
- Entrust representative — Entrust explained that the errata was added as a PDF comment and that the red strikethrough was intended to show the incorrect text.
- Entrust representative — Entrust said it was not relying on any authority for the non-revocation position and had opened bug 1890898 to address that issue.
- Entrust representative — Entrust clarified that the CPS was updated with an erratum in red so readers would see the corrected information.
- Entrust representative — Entrust updated the action table and marked the subscriber notice and errata items as done.
- Entrust representative — Entrust said all action items were complete and requested that the incident be closed.