← DigiCert cases
Bugzilla #1533655
Certificate Problem Report
DigiCert: Apple: Non-compliant Serial Numbers
RESOLVED
DigiCert
AI Summary
DigiCert identified that it had issued certificates with non-compliant serial numbers due to an issue with its CA software. The problem was detected on March 6, 2019, and was fixed within 24 hours. Affected certificates included approximately 878,000 TLS Server certificates and 2,400 S/MIME certificates. The CA has since revoked the majority of the impacted certificates and is working on a timeline for the remaining revocations.
Chronology
- Issue with non-compliant serial numbers detected
- Stopped issuance of non-compliant certificates
- Commenced revocation of impacted certificates
- All valid impacted certificates revoked
Participants
Apple CA
Ryan Sleevi
External References
Similar Local Cases
DigiCert: Apple: Unconstrained intermediate CAs not included in WTBR report
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
DigiCert: Underscores - Citi
DigiCert: Underscores - Verizon
DigiCert: Underscores - Ericsson
DigiCert: Underscores - Canadian Imperial Bank of Commerce
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: Underscores - Discover