Entrust: delayed revocation
This case concerns a delayed revocation by Entrust after a Certificate Problem Report (CPR) was submitted for a subscriber certificate key compromise. The reporter stated that the private key was compromised in the Fortigate leak and that the certificate was not yet revoked after the CPR was submitted to Entrust’s problem reporting address. Entrust confirmed that, after receiving a copy of the original email, it verified the key compromise and promptly revoked the affected certificate and blocked the compromised key. Entrust later provided an incident report stating that the CPR email had been quarantined as spam by Proofpoint and that the spam digest was sent only once every 24 hours and was not reviewed by the tracking system, so Entrust was unaware of the CPR until the Bugzilla bug was created. The incident report states the affected certificate was revoked on 2025-01-24 at 14:38 UTC, 36 hours and 47 minutes after the original CPR was submitted. Entrust committed to remediation steps including increasing the spam digest frequency to every 4 hours, checking the CPR mailbox for unprocessed messages and spam digest emails, and forwarding spam digest emails to support and compliance. Mozilla indicated it would close the bug on 19-Feb-2025, and the bug is marked RESOLVED with resolution FIXED.
- A CPR was submitted to Entrust’s official reporting email for a subscriber certificate key compromise.
- Entrust revoked the affected certificate after verifying the key compromise.
- Entrust submitted an incident report closure summary with remediation commitments and completion status.
- Mozilla closed the bug as FIXED.
- Hboeck representative — Reported that a certificate key compromise CPR sent to Entrust had not yet resulted in revocation and provided the affected certificate link.
- Entrust representative — Acknowledged the report, verified the key compromise after receiving the original email copy, and stated the certificate was promptly revoked and the compromised key blocked.
- Entrust representative — Provided an incident report explaining the CPR was quarantined as spam by Proofpoint and that infrequent, unreviewed spam digests contributed to delayed revocation, including a remediation timeline.
- Entrust representative — Submitted an incident report closure summary stating remediation actions were completed and requested closure.
- Mozilla representative — Indicated the bug would be closed on Wed. 19-Feb-2025.