← Google Trust Services LLC cases
Bugzilla #1532842 Certificate Misissuance

Google Trust Services: 63 bit serial numbers in some certificates

RESOLVED FIXED Google Trust Services LLC
AI Summary

Google Trust Services (GTS) identified that some certificates issued utilized EJBCA, resulting in serial numbers with only 63 bits of effective entropy, which is below the required standard. Upon discovering this issue, GTS acknowledged it as a misissuance but stated it did not pose a material security risk. They have since replaced and revoked approximately 95% of the affected certificates, with plans to address the remaining ones before their expiration. The incident was prompted by discussions regarding another CA's serial number generation issues, leading GTS to review their own practices.

Model: gpt-4o-mini Generated: 2026-06-13 18:06 UTC Confidence: 0.90
Chronology
  1. Concerns raised about serial entropy in Dark Matter certificates.
  2. GTS begins reviewing serial number generation behavior.
  3. GTS decides to replace and revoke all affected certificates.
  4. Certificate revocation begins.
  5. All remaining affected certificates were revoked.
Participants
ryan_hurst@hotmail.com ryan.sleevi@gmail.com awarner@google.com
External References
Similar Local Cases
#1809864 RESOLVED Certificate Misissuance Opened 2023-01-12 · Closed 2024-05-09 · 49% similar
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
#1547691 RESOLVED Certificate Misissuance Opened 2019-04-29 · Closed 2023-02-22 · 49% similar
GlobalSign: AT&T SSL certificates without the AIA extension
#1674082 RESOLVED Certificate Misissuance Opened 2020-10-29 · Closed 2023-02-22 · 48% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1552586 RESOLVED Certificate Misissuance Opened 2019-05-17 · Closed 2023-02-22 · 48% similar
GlobalSign: 4 Misissued certificates with invalid CN
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 47% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1528263 RESOLVED Certificate Misissuance Opened 2019-02-15 · Closed 2023-02-22 · 46% similar
Telia: Misissued certificate - Invalid wildcard format
#1408647 RESOLVED Certificate Misissuance Opened 2017-10-14 · Closed 2022-11-14 · 46% similar
Logius: Staat der Nederlanden CA trust issue (WiV)
#1524876 RESOLVED Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 41% similar
Entrust: IP in dnsName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action