PKIoverheid: KPN Insufficient Serial Number Entropy
The PKIoverheid CA identified a significant issue regarding insufficient entropy in the serial numbers of TLS certificates issued by KPN between September 30, 2016, and March 5, 2019. This problem was first noted during discussions in the Mozilla security policy community. Affected certificates were found to potentially include around 22,000 TLS certificates. The CA has since implemented a remediation plan, including the revocation of non-compliant certificates and the transition to using longer serial numbers. As of the latest updates, all affected certificates have been revoked, and measures have been put in place to prevent similar issues in the future.
- KPN begins investigation into serial number entropy issue.
- Logius PKIoverheid orders KPN to investigate and revoke affected certificates.
- All certificates in scope of Mozilla Policy have been CT logged.
- All affected certificates have been revoked.