TrustCor: Insufficient Serial Number Entropy
TrustCor reported a potential compliance issue involving certificate serial numbers after a discussion on mozilla.dev.security.policy. The report stated that certificates would contain a 64-bit serial number, but that depending on software configuration there was a high probability the most significant bit was 0, resulting in an effective entropy input of 63-bits and non-compliance with Section 7.1 of the Baseline Requirements. TrustCor initiated an immediate investigation and suspended issuance of all SSL certificates pending investigation. TrustCor performed operational testing for 96-bit serial numbers, confirmed downstream application compatibility, and then pushed the tested configuration into production; certificate issuance resumed using larger entropy. TrustCor identified five mis-issued certificates (all internal certificates), revoked them, and reissued the revoked certificates; it also verified certificate-related services (CRLs, OCSP, CT publication, etc.) with the new serial numbers. The bug was marked RESOLVED with resolution FIXED, and a later comment stated that remediation actions appeared to be completed. The thread also notes that TrustCor reviewed EJBCA settings after Ballot 164, concluded its interpretation of the 8-octet serial setting was incorrect, and revised its compliance process to require new monitoring code to be written, code-reviewed, and deployed before ballot effective dates.
- TrustCor became aware of a potential serial-number entropy issue and suspended SSL certificate issuance pending investigation.
- Operational testing for 96-bit serial numbers succeeded and downstream applications confirmed compatibility.
- TrustCor identified five mis-issued certificates, revoked them, completed configuration changes, resumed issuance with larger entropy, and reissued the revoked certificates.
- TrustCor verified certificate-related services (CRLs, OCSP, CT publication, etc.) worked with the new serial numbers.
- Community commenter — Posted an incident report describing the suspected serial-number entropy problem, TrustCor’s investigation timeline, suspension of issuance, revocation and reissuance of five mis-issued internal certificates, and verification of certificate services; included CT/crt.sh links for the revoked certificates.
- Community commenter — Described extending a serial-number scanning tool to use a compression-based test over a recent issuance window and generate alerts when the compression ratio falls below a threshold.
- Community commenter — Asked what steps TrustCor took after Ballot 164 to review/revisit existing settings and whether it led to process or policy changes for evaluating BR compliance.
- Community commenter — Stated TrustCor reviewed EJBCA settings for Ballot 164 compatibility, said its interpretation of the 8-octet serial setting was incorrect, and described a revised compliance process requiring new monitoring code to be written, reviewed, and deployed before ballot effective dates.
- Community commenter — Noted it appeared that all remediation actions had been completed.