Entrust: Incomplete privileged access removal within 24 hours
Entrust reported a compliance incident it discovered during a quarterly access review. The incident was that, on 2025-05-21, one infrastructure personnel’s privileged access to Certificate Systems was only partially disabled within 24 hours after termination of employment. Entrust cited Network and Certificate System Security Requirements Version 1.7, Section 2.l, which requires disabling all privileged access to Certificate Systems within 24 hours upon termination. Entrust stated that no certificates were impacted and that issuance was not stopped because the still-active privilege enabled an out-of-band network management application that did not provide access to any certificate issuance system. Entrust completed access removal on 2025-05-21 and reviewed audit logs to confirm no unauthorized access occurred. In its report closure summary, Entrust described remediation including updating the de-registration process to explicitly detail privileges to be removed, requiring an additional review by a second trusted role, and reviewing trusted role access monthly. The bug is marked RESOLVED with resolution FIXED.
- Non-compliance period began when a departing trusted role privilege was held for an out-of-band network management application.
- Entrust discovered during a quarterly access review that privileged access to Certificate Systems was not fully disabled within 24 hours after termination; access removal was completed the same day.
- Entrust posted the full incident report describing impact, root causes, and remediation.
- Entrust requested closure after completing action items described in the incident report.
- Entrust representative — Posted a preliminary incident report stating Entrust discovered during a quarterly access review that one infrastructure personnel’s privileged access to Certificate Systems was only partially disabled within 24 hours after termination.
- Entrust representative — Noted that the final incident report was being drafted and would be posted no later than 2025-06-04.
- Entrust representative — Posted the full incident report, stating CA CCADB unique ID A011701, that total certificates impacted was 0, and that no unauthorized access occurred per audit log review.
- Entrust representative — Indicated monitoring and that closure would be requested if there were no further comments.
- Entrust representative — Provided a report closure summary with remediation steps (explicit de-registration privileges, second trusted-role review, monthly trusted role access review) and requested closure.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2025-07-01.