Entrust: CRL missing revocation reasonCode
This case reports that Entrust’s CRLs for its TLS CAs did not include the revocation reasonCode in certain CRL entries. Entrust determined this based on evaluating monitoring alerts and stated that the issue was introduced by a recent software update, then mitigated by rolling back the update and reissuing the affected CRLs. Entrust reported that the revocation reasonCode was missing in CRLs for subordinate CAs for certificates revoked with reasons other than “unspecified reason,” and that the CRLs were corrected; it also stated that OCSP responses were not impacted. Entrust provided a root cause analysis stating that CRL generation code changes (using Go’s x509.CreateRevocationList API) and a unit test that used a mocked function meant the missing reasonCode was not detected by tests. Entrust listed action items including updating unit tests to use the same code as production, adding a functional test to validate CRL extension content, and improving monitoring to include reasonCode validation. Entrust later stated that all action items in the incident report were completed and requested closure, and Mozilla indicated it would close the bug on or about 5-Feb-2025.
- Entrust deployed a software update into production that included library updates affecting CRL generation.
- Entrust investigated monitoring alerts and confirmed the CRL reasonCode was missing, then rolled back the release and reissued affected CRLs.
- Entrust completed the incident action items, including adding functional testing and improving monitoring for reasonCode validation.
- Entrust representative — Entrust opened a preliminary incident report stating monitoring showed CRLs for TLS CAs lacked reasonCode for certain revocations, attributing it to a recent software update and noting the update was rolled back and CRLs reissued.
- Entrust representative — Entrust posted the full incident report with timeline, root cause analysis, impact (CRLs corrected; OCSP not impacted), and action items.
- Entrust representative — Entrust corrected a typo and listed action items with due dates.
- Entrust representative — Entrust stated it would continue to monitor.
- Entrust representative — Entrust requested the next update be set to 2025-01-31.
- Entrust representative — Entrust reported that all action items were completed and requested incident report closure.
- Mozilla representative — Mozilla stated it would close the bug on or about Wed. 5-Feb-2025.