← Entrust cases
Bugzilla #1890898 Ca Certificate Compliance Certificate Misissuance

Entrust incident report on OV TLS certificates and CPS text-placement error

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust opened this case to report 6,008 OV TLS certificates tied to a CPS Appendix A text-placement error. The initial report said the certificates were issued between 2024-03-22 and 2024-03-26, that Entrust self-discovered the CPS error, and that it initially did not plan to revoke the affected certificates because it believed the situation was exceptional. Mozilla and other commenters challenged that position and asked for clarification on revocation, remediation, and the basis for treating the case as non-revocable. On 2024-06-06, Entrust posted a revised analysis stating that the certificates had been mischaracterized as mis-issued, but later comments from Mozilla and Chrome disagreed with that view. On 2024-06-18, Entrust said it would treat the case as a mis-issuance and intended to complete revocation by end of day Saturday, 2024-06-22, with regular burndown updates to follow. The bug remained open for discussion of the revised characterization and revocation status.

Model: gpt-5.4-mini Generated: 2026-06-13 21:39 UTC Revised: 2026-06-16 16:27 UTC Confidence: 0.93 107 comments
Chronology
  1. Entrust posted CPS version 3.18 with an incorrect OV SSL profile text placement.
  2. Entrust discovered the CPS typographical error and posted CPS version 3.20 correcting it.
  3. Entrust filed an incident report and declared its intent not to revoke the affected certificates.
  4. Entrust posted a revised analysis saying the certificates were not mis-issued and did not need revocation.
  5. Entrust said it would treat the case as a mis-issuance and complete revocation by 2024-06-22.
Thread Activity
  1. Entrust representative — Entrust opened the bug and attached a list of affected certificates.
  2. Entrust representative — Entrust reported the incident, described the affected certificates, and said it did not plan to revoke them because it considered the situation exceptional.
  3. Community commenter — Asked what Entrust was doing to prevent a repeat of the failure to revoke.
  4. Entrust representative — Entrust said subscribers were informed of the CPS changes.
  5. Google representative — Asked Entrust to explain its reliance on low CPS download counts and what actions would prevent recurrence.
  6. Entrust representative — Entrust said the low download counts showed minimal impact and referred commenters to action items in the related bug.
  7. Entrust representative — Entrust posted a revised report saying the certificates were issued in accordance with the CPS and BRs, so there was no mis-issuance and no need to revoke.
  8. Community commenter — Asked whether Entrust had consulted its auditor and root stores about the analysis.
  9. Mozilla representative — Stated that a CA’s CPS is binding and that a certificate violating the CPS is still non-compliant.
  10. Google representative — Said a CA can change its opinion in some cases, but disagreed with Entrust’s revised position and said the certificates should have been revoked within 5 days.
  11. Entrust representative — Entrust said it would treat the case as a mis-issuance and intended to complete revocation by 2024-06-22.
  12. Google representative — Confirmed that re-characterizing the certificates later does not reset the revocation timer.
Participants
Entrust representative Community commenter Google representative Mozilla representative Sectigo Namepros representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1883843 RESOLVED Certificate Misissuance Opened 2024-03-06 · Closed 2024-08-13 · 100% similar
Entrust: EV TLS Certificate cPSuri missing
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 100% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 100% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1918380 RESOLVED Certificate Misissuance Opened 2024-09-12 · Closed 2024-11-06 · 95% similar
Entrust: Business Entity not permitted in CPS
#1667448 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 95% similar
Entrust: Incorrect keyUsage for ECC certificate
#1890685 RESOLVED Revocation Issue Certificate Misissuance Opened 2024-04-09 · Closed 2025-02-21 · 88% similar
Entrust: Failure to revoke EV TLS certificates issued before CPS update
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 87% similar
Entrust: IP in dnsName
#1567659 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 87% similar
Entrust: SHA-1 Issuance and other misissuance while testing

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action