← Entrust cases
Bugzilla #1918380 Certificate Misissuance

Entrust: Business Entity not permitted in CPS

RESOLVED FIXED Entrust
AI Summary

Entrust discovered that it had mis-issued nine certificates to Business Entities, contrary to its Certification Practice Statement (CPS). This issue arose during a compliance review, leading to the immediate halting of certificate issuance for Business Entity Subscribers. The mis-issued certificates included two EV Code Signing and seven VMC certificates. Entrust has taken steps to revoke these certificates and update its CPS to prevent future occurrences. A full incident report detailing the root cause and corrective actions is being prepared.

Model: gpt-4o-mini Generated: 2026-06-13 21:41 UTC Confidence: 0.95
Chronology
  1. Investigation initiated into certificate issuance practices.
  2. CPS updated and mis-issued certificates revoked.
  3. All action items completed; request to close the bug.
Participants
Bruce Morton
Similar Local Cases
#1561013 RESOLVED Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 62% similar
Entrust: Certificate issued with validity greater than 825-days
#1890896 RESOLVED Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 61% similar
Entrust: CPS typographical (text placement) error
#1673119 RESOLVED Certificate Misissuance Opened 2020-10-23 · Closed 2023-02-22 · 60% similar
Entrust: Subscriber provides private key with CSR
#1906467 RESOLVED Certificate Misissuance Opened 2024-07-05 · Closed 2025-05-13 · 59% similar
Entrust: S/MIME mailbox address not in subjectAltName
#1914065 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2025-02-28 · 59% similar
Entrust: S/MIME certificates lacking OU verification
#1914999 RESOLVED Certificate Misissuance Opened 2024-08-26 · Closed 2025-02-28 · 59% similar
Entrust: S/MIME OrgID Country not matching C field
#1648472 RESOLVED Certificate Misissuance Opened 2020-06-25 · Closed 2024-06-30 · 59% similar
Entrust: SHA-256 hash algorithm used with ECC P-384 key
#1890898 RESOLVED Certificate Misissuance Opened 2024-04-11 · Closed 2024-07-28 · 58% similar
Entrust: Failure to revoke OV TLS - CPS typographical (text placement) error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action