Entrust: Delayed Revocation for S/MIME certificates
This case concerns Entrust S/MIME certificates that were revoked after the 5-day revocation deadline. Entrust reported that three S/MIME sponsor-validated certificates were revoked beyond the 5-day deadline by hours (12:08, 00:47, and 11:14). Entrust said it previously measured the 5-day revocation timeline from when mis-issuance was confirmed after post-issuance linting flagged potential errors, rather than from when the issue was reported/received. Entrust stated that this approach was based on its interpretation of S/MIME BR section 4.9.1.1 and that it updated its practice after comment feedback, to start the 5-day revocation period when an issue is reported (i.e., when the CPR or internal report is received). In the thread, Entrust also described action items to change its issue management process and to implement pre-sign linting for S/MIME. Entrust later reported that pre-sign linting was deployed on 2024-11-07 and that all actions were completed, requesting closure; the bug is marked RESOLVED with resolution FIXED.
- Post-issuance linting flagged an error in an S/MIME certificate (mailbox address not found in SAN).
- Entrust determined mis-issuance for one S/MIME certificate and began analysis for additional certificates.
- Entrust revoked three mis-issued S/MIME certificates after its investigation/confirmation process.
- Entrust reported pre-sign linting for S/MIME was deployed and all action items were completed.
- Entrust representative — Entrust submitted an incident report describing three S/MIME certificates revoked beyond the 5-day deadline and explaining that it previously started the revocation clock after confirmation of mis-issuance, then updated its practice to start when an issue is reported.
- Community commenter — A forum participant suggested Entrust should know the revocation clock does not start after human verification and referenced other threads discussing when the clock starts.
- Entrust representative — Entrust stated it updated its issue management process to start the revocation period when the CPR or internal report is received.
- Entrust representative — Entrust reported pre-sign linting implementation for S/MIME was on track and requested a new next update date.
- Entrust representative — Entrust reported it was on track to implement pre-sign linting for S/MIME before 2024-11-30 and requested a new next update date.
- Entrust representative — Entrust reported action items were completed, including pre-sign linting deployed on 2024-11-07, and requested the bug be closed.
- Mozilla representative — Mozilla stated it would consider closing the bug on or about 13-Nov-2024 unless there was ongoing discussion.