Atos: duplicate serial numbers
The case concerns a report that Atos had two intermediate certificates with the same Issuer and Serial Number for “Atos TrustedRoot CodeSigning-CA 2011” and for “Atos TrustedRoot Server-CA 2011.” The reporter provided links to the affected certificates on crt.sh. Kathleen Wilson noted that the certificates were already revoked and asked Atos to describe the mechanisms in place to prevent issuing certificates with duplicate serial numbers. Martin Kramer from Atos responded that the issue had already been discussed during Atos’s Root Inclusion request, linking to a Mozilla developer security policy thread. Kathleen then stated that the matter was previously resolved and resolved the bug as a duplicate of Bug 711366, which had triggered the earlier discussion. The bug is currently marked as RESOLVED with resolution DUPLICATE.
- A bug was filed regarding duplicate serial numbers on Atos intermediate certificates for two Atos TrustedRoot hierarchies.
- The bug was resolved as a duplicate of Bug 711366 after referencing prior discussion and resolution.
- Sectigo — Reported that two intermediate certs for each of two Atos TrustedRoot CA names shared the same Issuer and Serial Number, with crt.sh links.
- Mozilla representative — Asked Atos to add a comment describing mechanisms to ensure certificates cannot be issued with duplicate serial numbers, noting the certs were revoked and created before 01-Jul-2012.
- Atos — Said the issue was already discussed during the Root Inclusion request and linked to a Mozilla developer security policy thread.
- Mozilla representative — Confirmed the issue was previously resolved, referenced the prior message, and resolved this bug as a duplicate of Bug 711366.