← DigiCert cases
Bugzilla #1417777 Certificate Problem Report

DigiCert: Insufficient entropy in serial numbers

RESOLVED DigiCert
AI Summary

DigiCert identified an issue where their validation system used random numbers with insufficient entropy for email validations, utilizing only 77 bits instead of the required 112 bits. The problem was reported on November 1, 2017, and a patch was implemented on November 3, 2017, to correct the entropy levels. The incident affected a significant number of certificates issued under the old system, but no further issues were found in other systems. DigiCert has since taken steps to ensure compliance with the required standards.

Model: gpt-4o-mini Generated: 2026-06-13 11:17 UTC Confidence: 0.90
Chronology
  1. Issue reported by partner CTJ
  2. Investigation began
  3. Patch implemented to fix entropy issue
Participants
Jeremy Rowley
External References
Similar Local Cases
#1397951 RESOLVED Certificate Problem Report Opened 2017-09-07 · Closed 2023-02-22 · 62% similar
DigiCert / InfoCert: Insufficient Serial Number Entropy
#1389172 RESOLVED Certificate Problem Report Opened 2017-08-10 · Closed 2023-02-22 · 62% similar
DigiCert: Certificate Issues Identified on the Mailing List
#1727963 RESOLVED Certificate Problem Report Opened 2021-08-28 · Closed 2023-02-22 · 60% similar
DigiCert: Truncation of Registration Number
#1429639 RESOLVED Certificate Problem Report Opened 2018-01-11 · Closed 2023-02-22 · 60% similar
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs
#1304895 RESOLVED Certificate Problem Report Opened 2016-09-22 · Closed 2023-02-22 · 60% similar
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
#1518555 RESOLVED Certificate Problem Report Opened 2019-01-08 · Closed 2023-02-22 · 59% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm
#1516453 RESOLVED Certificate Problem Report Opened 2018-12-26 · Closed 2023-02-22 · 59% similar
DigiCert: Underscores - Discover
#1483715 RESOLVED Certificate Problem Report Opened 2018-08-15 · Closed 2024-06-30 · 59% similar
DigiCert: improper use of domain validation method

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action