Entrust: Cross-certified CA CP/CPS not updated in CCADB
This case concerns an incident where Entrust’s CCADB record for a cross-certified CA (SSL.com) had CP/CPS information that was out of sync. Entrust received notice on 2025-03-25 from Sectigo that crt.sh was flagging an inconsistent CPS issue for SSL.com, and that the CCADB record under Entrust’s control had not been updated after SSL.com updated its CP/CPS. Entrust stated that SSL.com had marked its previous CP/CPS version as “Superseded” in CCADB, and that this propagated such that the Entrust-controlled CCADB record only had “Superseded” CP/CPS info. Entrust updated the CP/CPS information in CCADB on 2025-03-25 approximately 14:30 UTC, and reported that there were no mis-issued certificates and minimal impact to subscribers and relying parties. In the full incident report, Entrust attributed the root cause to communications gaps between Entrust and SSL.com after the WebTrust for RA point-in-time audit, and to a process that did not ensure the cross-certificate information owner was advised of CP/CPS updates. Entrust’s remediation included implementing a standing monthly call and updating procedures to ensure timely, process-driven updates for cross-certificate CA information. The bug is marked RESOLVED with resolution FIXED, and Entrust requested closure after stating all action items were completed.
- Entrust updated the SSL.com CP/CPS information in CCADB after receiving notice that the CCADB record was out of sync.
- Entrust representative — Entrust posted a preliminary incident report describing a Sectigo notice about an inconsistent CPS issue and stating Entrust updated CCADB on 2025-03-25 around 14:30 UTC.
- Entrust representative — Entrust reposted the preliminary incident report in the correct format, reiterating the incident description and the 14-day CCADB policy disclosure requirement.
- Entrust representative — Entrust stated it was drafting the final incident report.
- Entrust representative — Entrust posted the full incident report, including timeline, root cause analysis, and remediation steps.
- Entrust representative — Entrust posted a report closure summary with remediation details (monthly call and updated procedure) and requested closure.
- Entrust representative — Entrust stated it was continuing to monitor the bug, that all items were completed, and requested bug closure.
- Entrust representative — Entrust again stated all items were completed and requested bug closure.
- CCADB representative — CCADB incident reporting posted a final call for comments and noted the bug would be closed on approximately 2025-05-08.