← Entrust cases
Bugzilla #1906470
Ca Certificate Compliance
Certificate Misissuance
Closure Request
Entrust: S/MIME mailbox address case mismatch between subject and subjectAltName
RESOLVED
FIXED
Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Entrust identified a compliance issue involving two S/MIME certificates that were issued with a mailbox address case mismatch between the subject name and the subjectAltName. This was discovered during an internal investigation triggered by a pkilint error reported in another bug. As a result, Entrust halted S/MIME certificate issuance, revoked the impacted certificates, and implemented a software fix to prevent future occurrences. A full incident report was prepared, detailing the root cause and remediation steps, including the deployment of pre-sign linting for S/MIME certificates.
Chronology
- Internal certificate problem report received, leading to investigation.
- Impacted certificates were revoked.
- Pre-sign linting for S/MIME deployed.
Thread Activity
- Entrust representative — Received internal notification of a pkilint error about potential certificate mis-issuance.
- Entrust representative — The impacted certificates were revoked.
- Entrust representative — All actions are completed. We request this bug be closed.
Participants
Entrust representative
Mozilla representative
External References
Similar Local Cases
Entrust: clientAuth TLS Certificates without serverAuth EKU
Entrust: Delay in Updating CPS
Entrust: CPS typographical (text placement) error
Entrust: S/MIME mailbox address not in subjectAltName
Entrust: S/MIME certificates lacking OU verification
Entrust: Incorrect Business Category Value Discovered in an EV SSL Certificate
Entrust: Invalid localityName
Entrust: SSL Certificates issued with Un-verified IP Addresses