Atos duplicate serial numbers in intermediate certificates
This case concerns two Atos intermediate certificates that were issued with the same issuer and serial number. The reporter identified duplicate serial numbers in the Atos TrustedRoot CodeSigning-CA 2011 and Atos TrustedRoot Server-CA 2011 intermediates and linked to the affected certificates on crt.sh. Mozilla asked Atos to explain what controls were in place to prevent duplicate serial-number issuance, noting that the certificates had already been revoked and were created before the first BR effective date of 2012-07-01. Atos replied that the issue had already been discussed during its root inclusion request. Mozilla then marked the bug as a duplicate of Bug 711366 and resolved it as DUPLICATE.
- Two Atos intermediate certificates were identified with duplicate issuer and serial numbers.
- Mozilla asked Atos to explain what mechanisms prevent duplicate serial-number issuance.
- Mozilla resolved the bug as a duplicate of Bug 711366.
- Sectigo — Reported duplicate serial numbers in two Atos intermediate certificates and provided crt.sh links.
- Mozilla representative — Noted the certificates were revoked and asked Atos to describe controls preventing duplicate serial numbers.
- Atos — Said the issue had already been discussed during Atos's root inclusion request.
- Mozilla representative — Stated the matter was previously resolved and marked the bug a duplicate of Bug 711366.