Entrust: Delayed incident report — CPS typographical (text placement) error
Entrust reported a delayed incident disclosure related to a typographical error in its CPS (text placement). Entrust stated that it self-discovered the CPS typographical error on 2024-03-26, updated the CPS to correct it, and posted CPS version 3.20 the same day. Entrust said the incident report was published 15 days later, and it provided transparency for that delayed publication. The incident involved 6,008 OV TLS certificates issued between 2024-03-22 15:02 UTC and 2024-03-26 17:07 UTC, with a validity mode of 392 days. Entrust attributed the delay to concurrent incidents and capacity constraints, noting that incident management and report drafting were affected by other ongoing work and the large number of subscribers affected. The bug was resolved as FIXED, and Mozilla later closed the bug while noting it would still appear on the list of Entrust compliance issues being drafted.
- Entrust self-discovered a typographical error in its CPS, updated the CPS, and posted CPS version 3.20.
- Entrust published the incident report for the delayed disclosure.
- Mozilla closed the bug (as indicated by the intended close date and subsequent closure).
- Entrust representative — Entrust posted an incident report explaining the delayed publication, the affected certificate count and issuance window, and the root cause and delay rationale.
- Entrust representative — Entrust stated there were no updates and it would continue to monitor the bug.
- Entrust representative — Entrust stated there were no updates and it would continue to monitor the bug.
- Mozilla representative — Mozilla stated it intended to close the bug on 2024-05-03.
- Community commenter — A commenter questioned closing because action items were linked to another bug not yet remediated.
- Mozilla representative — Mozilla said it would respond concerning Entrust’s issues, incidents, responses, and remediation efforts in due course.
- Community commenter — The commenter reiterated a preference for the response to start before closing the marked bugs.
- Entrust representative — Entrust stated there were no updates and it would continue to monitor the bug.
- Mozilla representative — Mozilla closed the bug and stated it would still appear on the list of Entrust compliance issues being drafted.