← SSL.com cases
Bugzilla #1534147
Certificate Problem Report
SSL.com: Insufficient serial number entropy
RESOLVED
FIXED
SSL.com
AI Summary
SSL.com identified an issue with insufficient entropy in the serial number generation of their certificates, which was linked to their use of EJBCA. Following discussions in the mozilla.dev.security.policy forum, SSL.com initiated a review and confirmed the issue on March 5, 2019. They promptly deployed a patch and resumed certificate issuance with corrected serial number generation. Affected certificates were revoked, and a comprehensive remediation plan was implemented to prevent future occurrences.
Chronology
- Ballot 164 on Certificate Serial Number Entropy is voted.
- Ballot 164 enters into effect.
- Initial review initiated and issue confirmed.
- Plan for revocation of affected certificates initiated.
- Revocation of affected TLS end-entity certificates completed.
Participants
Wayne Thayer
Fotis Loukos
External References
Similar Local Cases
SSL.com: Issued precertificate with Debian Weak Key
TrustCor: Insufficient Serial Number Entropy
SSL.com: Failure to process CAA records from one SubCA
GoDaddy: Insufficient serial number entropy
SSL.com: Issuance of certificates using keys previously reported as compromised
Buypass: Insufficient Serial Number Entropy
GlobalSign: AT&T Insufficient Serial Number Entropy
Consorci AOC: Non-BR-Compliant Certificate Issuance