QuoVadis: DarkMatter Insufficient Serial Number Entropy
DarkMatter LLC faced an incident regarding insufficient entropy in certificate serial numbers, which was reported by Corey Bonnell on February 23, 2019. The issue stemmed from the generation of 64-bit serial numbers, which was deemed non-compliant with the Baseline Requirements. Following an internal investigation, DarkMatter confirmed compliance but decided to revoke 175 certificates as a precaution. Subsequent updates included scheduled key ceremonies to address the root certificates and the re-issuance of affected certificates. The case was ultimately resolved with remediation actions completed by April 2019.
- Incident reported by Corey Bonnell regarding serial number entropy.
- DarkMatter revoked all active public trust TLS certificates with 64-bit serial numbers.
- Key ceremonies scheduled to update root certificates.
- Final batch of SubCAs re-issued.
- Remediation confirmed complete.