← TrustCor Systems cases
Bugzilla #1532399 Ca Certificate Compliance Self Reported Incident

TrustCor: Insufficient Serial Number Entropy

RESOLVED FIXED TrustCor Systems
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TrustCor reported a potential compliance issue involving certificate serial numbers after a discussion on mozilla.dev.security.policy. The report stated that certificates would contain a 64-bit serial number, but that depending on software configuration there was a high probability the most significant bit was 0, resulting in an effective entropy input of 63-bits and non-compliance with Section 7.1 of the Baseline Requirements. TrustCor initiated an immediate investigation and suspended issuance of all SSL certificates pending investigation. TrustCor performed operational testing for 96-bit serial numbers, confirmed downstream application compatibility, and then pushed the tested configuration into production; certificate issuance resumed using larger entropy. TrustCor identified five mis-issued certificates (all internal certificates), revoked them, and reissued the revoked certificates; it also verified certificate-related services (CRLs, OCSP, CT publication, etc.) with the new serial numbers. The bug was marked RESOLVED with resolution FIXED, and a later comment stated that remediation actions appeared to be completed. The thread also notes that TrustCor reviewed EJBCA settings after Ballot 164, concluded its interpretation of the 8-octet serial setting was incorrect, and revised its compliance process to require new monitoring code to be written, code-reviewed, and deployed before ballot effective dates.

Model: gpt-5.4-nano Generated: 2026-06-13 18:05 UTC Revised: 2026-06-16 18:12 UTC Confidence: 0.90 5 comments
Chronology
  1. TrustCor became aware of a potential serial-number entropy issue and suspended SSL certificate issuance pending investigation.
  2. Operational testing for 96-bit serial numbers succeeded and downstream applications confirmed compatibility.
  3. TrustCor identified five mis-issued certificates, revoked them, completed configuration changes, resumed issuance with larger entropy, and reissued the revoked certificates.
  4. TrustCor verified certificate-related services (CRLs, OCSP, CT publication, etc.) worked with the new serial numbers.
Thread Activity
  1. Community commenter — Posted an incident report describing the suspected serial-number entropy problem, TrustCor’s investigation timeline, suspension of issuance, revocation and reissuance of five mis-issued internal certificates, and verification of certificate services; included CT/crt.sh links for the revoked certificates.
  2. Community commenter — Described extending a serial-number scanning tool to use a compression-based test over a recent issuance window and generate alerts when the compression ratio falls below a threshold.
  3. Community commenter — Asked what steps TrustCor took after Ballot 164 to review/revisit existing settings and whether it led to process or policy changes for evaluating BR compliance.
  4. Community commenter — Stated TrustCor reviewed EJBCA settings for Ballot 164 compatibility, said its interpretation of the 8-octet serial setting was incorrect, and described a revised compliance process requiring new monitoring code to be written, reviewed, and deployed before ballot effective dates.
  5. Community commenter — Noted it appeared that all remediation actions had been completed.
Participants
Community commenter
Similar Local Cases
#1568356 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-23 · Closed 2023-02-22 · 92% similar
TrustCor: Incorrect CA-Issuers URI
#1599503 RESOLVED Self Reported Incident Opened 2019-11-26 · Closed 2024-06-30 · 80% similar
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports
#1512018 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-12-04 · Closed 2023-02-22 · 78% similar
Entrust: Certificate issued with '-' in ST field
#1622539 RESOLVED Self Reported Incident Opened 2020-03-14 · Closed 2023-02-22 · 77% similar
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
#1561013 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-24 · Closed 2023-02-22 · 76% similar
Entrust: Certificate issued with validity greater than 825-days
#1429639 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-01-11 · Closed 2023-02-22 · 76% similar
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs
#1551369 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-05-14 · Closed 2023-02-22 · 75% similar
Kamu SM: "Some-State" in stateOrProvinceName
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 75% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action