Entrust: Missing or Inconsistent Disclosure of S/MIME BR Audits
Entrust reported an inconsistency in their S/MIME Baseline Requirements (BR) audit report, specifically regarding the omission of certain roots trusted for S/MIME. The issue was identified on March 5, 2025, following a notice received from a third party. Entrust acknowledged that six roots, which have S/MIME issuance capabilities but have not issued any S/MIME CA certificates, were mistakenly excluded from the audit scope. The CA has committed to including these roots in the upcoming audit report due by May 31, 2025, and has updated its compliance procedures to prevent future omissions. No mis-issued certificates were involved in this incident.
- Entrust identified missing roots in their S/MIME BR audit report.
- Entrust plans to post an updated S/MIME BR audit report.
- Entrust representative — Entrust received notice about the missing roots in the S/MIME BR audit report.
- Entrust representative — Entrust completed action items related to the incident and requested closure of the bug.