Google Trust Services: 63 bit serial numbers in some certificates
Google Trust Services (GTS) identified that some certificates issued utilized EJBCA, resulting in serial numbers with an effective entropy of only 63 bits, which is a violation of the Baseline Requirements. Upon discovering this issue, GTS acknowledged the misissuance and began a remediation process, replacing and revoking approximately 95% of the affected certificates. The remaining certificates were set to expire within three months, and GTS committed to revoking any outstanding certificates by March 31, 2019. GTS has since updated its serial number generation logic to ensure compliance with the Baseline Requirements.
- GTS begins reviewing the serial number generation behavior of its CAs after concerns were raised.
- GTS decides to replace and revoke all affected certificates.
- All remaining affected certificates were revoked.
- Community commenter — GTS reports on the issue and outlines the steps taken to mitigate the problem.
- Community commenter — GTS provides a final update confirming the completion of remediation actions.