DigiCert / Siemens: Insufficient Serial Number Entropy
This case involves DigiCert's disclosure of insufficient serial number entropy in certificates issued by its sub-CA, Siemens. The issue was identified following a certificate problem report, prompting DigiCert to notify Siemens and schedule a revocation of the affected certificates. Siemens failed to revoke the certificates within the required 24-hour timeframe, leading to further discussions and a planned revocation on September 15, 2017. As of that date, all problematic certificates were revoked, and DigiCert filed a separate bug to include the Siemens CA in OneCRL. The situation has since been resolved with the necessary actions taken to prevent future occurrences.
- Revocation of all certificates issued by Siemens with insufficient serial number entropy.
- Mozilla representative — Requested an incident report specific to Siemens due to insufficient serial number entropy.
- DigiCert — Confirmed that Siemens did not revoke certificates in time and provided details on the issue.
- Siemens representative — Informed that Siemens contacted customers about the impending certificate invalidation.
- Siemens representative — Confirmed that all certificates from the affected CA were revoked.