← Entrust cases
Bugzilla #1943528
Certificate Problem Report
Entrust: delayed revocation
RESOLVED
FIXED
Entrust
AI Summary
Entrust received a Certificate Problem Report (CPR) regarding a compromised private key on January 22, 2025, but was unaware of it until a Bugzilla case was created on January 24. The CPR was quarantined by their email protection system, leading to a delay in revocation. The affected certificate was revoked on January 24, 2025, after verification of the compromise. Entrust has since updated their procedures to ensure timely handling of CPRs and prevent future occurrences.
Chronology
- CPR submitted for key compromise
- Bugzilla case created; CPR verified and certificate revoked
- Incident report detailing root cause and remediation steps provided
- Incident report closure summary submitted
Participants
Hanno Boeck
Paul van Brouwershaven
Bruce Morton
B Wilson
External References
Similar Local Cases
Entrust: SSL Certificates issued with Un-verified IP Addresses
Entrust: TLS Certificate issued with an incorrect state or province
Entrust: clientAuth TLS Certificates without serverAuth EKU
Entrust: Delayed Revocation for S/MIME certificates
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
Entrust: Failure to revoke a certificate
Entrust: CRL missing revocation reasonCode
Entrust: Certificate issued with '-' in ST field