Re: Recent Entrust Compliance Incidents

2024-05-10 Thread 'Ben Wilson' via dev-security-policy@mozilla.org
Added " Although not expressed in the bug, it appears that certificate revocation was delayed as well." On Fri, May 10, 2024 at 10:54 AM George wrote: > Although it was not mentioned in the original bug, it may be worth adding > that the certificates in bug 1867130 >

Re: Recent Entrust Compliance Incidents

2024-05-10 Thread 'George' via dev-security-policy@mozilla.org
Although it was not mentioned in the original bug, it may be worth adding that the certificates in [bug 1867130](https://bugzilla.mozilla.org/show_bug.cgi?id=1867130) were also not revoked within 5 days of discovery. Entrust might've based the start of the 5 day deadline at the time the

Re: Recent Entrust Compliance Incidents

2024-05-10 Thread 'Ben Wilson' via dev-security-policy@mozilla.org
Here are draft summaries of the additional historic incidents. I'll be adding these to the Entrust Issues page: https://wiki.mozilla.org/CA/Entrust_Issues *Invalid data in State/Province Field -* https://bugzilla.mozilla.org/show_bug.cgi?id=1658792 It was initially discovered that Entrust had