Entrust incident report on OV TLS certificates and CPS text-placement error
Entrust opened this case to report 6,008 OV TLS certificates tied to a CPS Appendix A text-placement error. The initial report said the certificates were issued between 2024-03-22 and 2024-03-26, that Entrust self-discovered the CPS error, and that it initially did not plan to revoke the affected certificates because it believed the situation was exceptional. Mozilla and other commenters challenged that position and asked for clarification on revocation, remediation, and the basis for treating the case as non-revocable. On 2024-06-06, Entrust posted a revised analysis stating that the certificates had been mischaracterized as mis-issued, but later comments from Mozilla and Chrome disagreed with that view. On 2024-06-18, Entrust said it would treat the case as a mis-issuance and intended to complete revocation by end of day Saturday, 2024-06-22, with regular burndown updates to follow. The bug remained open for discussion of the revised characterization and revocation status.
- Entrust posted CPS version 3.18 with an incorrect OV SSL profile text placement.
- Entrust discovered the CPS typographical error and posted CPS version 3.20 correcting it.
- Entrust filed an incident report and declared its intent not to revoke the affected certificates.
- Entrust posted a revised analysis saying the certificates were not mis-issued and did not need revocation.
- Entrust said it would treat the case as a mis-issuance and complete revocation by 2024-06-22.
- Entrust representative — Entrust opened the bug and attached a list of affected certificates.
- Entrust representative — Entrust reported the incident, described the affected certificates, and said it did not plan to revoke them because it considered the situation exceptional.
- Community commenter — Asked what Entrust was doing to prevent a repeat of the failure to revoke.
- Entrust representative — Entrust said subscribers were informed of the CPS changes.
- Google representative — Asked Entrust to explain its reliance on low CPS download counts and what actions would prevent recurrence.
- Entrust representative — Entrust said the low download counts showed minimal impact and referred commenters to action items in the related bug.
- Entrust representative — Entrust posted a revised report saying the certificates were issued in accordance with the CPS and BRs, so there was no mis-issuance and no need to revoke.
- Community commenter — Asked whether Entrust had consulted its auditor and root stores about the analysis.
- Mozilla representative — Stated that a CA’s CPS is binding and that a certificate violating the CPS is still non-compliant.
- Google representative — Said a CA can change its opinion in some cases, but disagreed with Entrust’s revised position and said the certificates should have been revoked within 5 days.
- Entrust representative — Entrust said it would treat the case as a mis-issuance and intended to complete revocation by 2024-06-22.
- Google representative — Confirmed that re-characterizing the certificates later does not reset the revocation timer.