Entrust: Business Entity not permitted in CPS (mis-issued EV Code Signing and VMC certificates)
Entrust reported that its CPS version 3.22 stated that it does not issue certificates to Business Entity subjects, but an investigation found that Entrust does verify Business Entity subjects and had issued certificates to Business Entities. The case involved nine mis-issued certificates (2 EV Code Signing and 7 VMC) issued to nine different subscribers. Entrust halted certificate issuance for Business Entity subscribers by resetting/re-opening their clients to require complete verification before issuance. Entrust notified subscribers of the mis-issuance and revoked all affected certificates, with revocation completed on 2024-09-15. Entrust stated it updated the CPS to correct the issue and planned additional process changes, including establishing a Certificate Services Compliance Change Management Policy and ensuring practice owners review CPS changes. The bug thread indicates all action items were completed and requests closure, with Mozilla stating it would close the bug on 6-Nov-2024 unless additional issues were raised.
- Entrust investigated whether it issues certificates to Business Entity subjects and determined mis-issuance occurred.
- Entrust halted certificate issuance for Business Entity subscribers by resetting/re-opening their clients to require complete verification.
- Entrust advised subscribers of the mis-issuance.
- Entrust published a CPS update to correct the Business Entity statement.
- Entrust revoked all mis-issued certificates.
- Entrust reported completion of action items and requested the bug be closed.
- Entrust representative — Opened a preliminary incident report stating CPS said Business Entity subjects were not issued, but investigation found 2 EV Code Signing and 7 VMC certificates were mis-issued to Business Entities; subscribers were notified and issuance was halted for Business Entity subscribers.
- Entrust representative — Reported work on the incident report and planned posting by 2024-09-24.
- Entrust representative — Posted the incident report with timeline, impact, root cause analysis, and lessons learned, including that all certificates were revoked on 2024-09-15.
- Entrust representative — Requested the next update be 2024-10-31 and said Entrust would continue to monitor.
- Entrust representative — Listed action items and stated all actions were complete, requesting closure of the bug.
- Mozilla representative — Indicated Mozilla would look at closing the bug on 6-Nov-2024 and asked for any additional questions/issues before then.