Re: Entrust-issued certificate with compromised private key.

2020-01-23 Thread Dathan Demone via dev-security-policy
On Tuesday, 21 January 2020 15:49:30 UTC-5, Dathan Demone wrote: > On Tuesday, 21 January 2020 14:07:49 UTC-5, Benjamin Seidenberg wrote: > > > One - which appears to remain valid at time of writing - is an OV > > > certificate for "routerlogin.com" and variants, which was issued to > > >

Re: Entrust-issued certificate with compromised private key.

2020-01-21 Thread Dathan Demone via dev-security-policy
On Tuesday, 21 January 2020 14:07:49 UTC-5, Benjamin Seidenberg wrote: > > One - which appears to remain valid at time of writing - is an OV > > certificate for "routerlogin.com" and variants, which was issued to Netgear > > by Entrust, https://crt.sh/?id=1955992027 > > > > Based on this

Re: Entrust-issued certificate with compromised private key.

2020-01-21 Thread Dathan Demone via dev-security-policy
On Tuesday, 21 January 2020 09:43:53 UTC-5, teg...@gmail.com wrote: > About 24 hours ago, this gist was published to Github: > > https://gist.github.com/nstarke/a611a19aab433555e91c656fe1f030a9 > > It details two publicly-trusted certificates whose private keys are present > in

Incident Report - EV Certificates Issued with Business Category "Non-Commercial" when it should have been set to "Private Organization"

2019-11-27 Thread Dathan Demone via dev-security-policy
On November 25th, Entrust Datacard was made aware of possible EV certificate mis-issuance due to incorrect values in the Business Category field. A link to the incident report can be found here: https://bugzilla.mozilla.org/show_bug.cgi?id=1599484 Dathan Demone Entrust Datacard - Verification