Entrust delayed revocation report for jurisdiction-related EV TLS and Code Signing certificates
Entrust opened this bug to report delayed revocation handling for some EV TLS and Code Signing certificates affected by a jurisdiction-data issue. Entrust said the underlying incident was created on 2024-05-18, but the affected certificates had already been revoked or expired by 2024-05-21, and the report was filed because Entrust believed it should have detected, escalated, and confirmed the issue earlier. In the thread, Entrust explained that the delay was caused by insufficient processes and resources, including reliance on manual communication and escalation paths that were vulnerable to human error. Entrust later said it should have declared the mis-issuance and halted issuance on 2024-04-04, and it provided action items covering policy review, internal reporting improvements, team reorganization, additional input validation, and pkilint deployment. Mozilla kept the bug open for review for some time, and Entrust repeatedly asked for closure after stating that all action items were completed. The closure summary states that revocation had been delayed to minimize harm to subscribers and relying parties, and that Entrust had changed its revocation position to revoke all non-expired certificates.
- Entrust created the underlying incident report for jurisdiction-data issues in some EV TLS and Code Signing certificates.
- All affected certificates were revoked or had expired.
- Entrust said it had revoked all affected certificates within five days after confirming the incident and published remediation actions.
- Entrust reported that all listed action items were done and requested closure.
- Entrust filed a closure summary stating revocation had been delayed to minimize harm and that it would revoke all non-expired certificates.
- Entrust representative — Entrust said it was submitting the report because it had not investigated, escalated, confirmed, reported, and revoked quickly enough to meet required timeframes.
- Entrust representative — Entrust said the existing processes were insufficient because they were vulnerable to human error, had bottlenecks, lacked automation, and did not scale well.
- Entrust representative — Entrust listed near-term actions including expanding linters, formalizing delayed revocation handling, and improving subscriber education.
- Entrust representative — Entrust said no subscribers requested delayed revocation and that all affected certificates were revoked within five days after the incident was confirmed.
- Entrust representative — Entrust posted action items including policy review, internal reporting improvements, team reorganization, input validation, and pkilint deployment.
- Entrust representative — Entrust said all action items were completed and requested that the incident be closed.
- Entrust representative — Entrust provided a closure summary describing the incident, root cause, remediation, and commitment to Baseline Requirements compliance.