SSL.com: Insufficient serial number entropy
This case reports that SSL.com, which uses EJBCA internally, identified an issue affecting certificate serial number generation that could violate CA/B Forum Baseline Requirements (BR 7.1). SSL.com said it became aware of the problem by following discussions on mozilla.dev.security.policy and initiated a review on 2019-03-05, confirming the issue existed in SSL.com certificates. SSL.com deployed a correction to production systems on 2019-03-05 and resumed certificate issuance with serials meeting the requirements. SSL.com also initiated a plan to revoke affected certificates, including a timeline to revoke affected CA and end-entity TLS certificates by 2019-04-06, and to handle affected S/MIME certificates differently based on its interpretation of requirements. SSL.com stated that it would revoke CA and end-entity TLS certificates affected by 2019-04-06, and that it agreed with an interpretation for S/MIME certificates and would not revoke certificates not used in the WebPKI and not under the CA/B Forum Baseline Requirements; it said it reissued affected S/MIME issuing CAs and began deprecating the old ones. In the thread, the reporter later confirmed that all TLS certificates had been revoked, and described remediation efforts beyond the immediate issue.
- SSL.com initiated a review of an EJBCA serial number entropy issue and deployed a correction to production systems.
- SSL.com initiated a plan to revoke all certificates affected by the serial number issue.
- SSL.com performed a key ceremony to issue replacement CA certificates.
- SSL.com resumed issuance of new end-entity certificates using replacement CA certificates and prepared subscriber notifications.
- SSL.com revoked affected TLS end-entity certificates per the remediation timeline.
- SSL.com approved a final incident report by management.
- Fastly representative — Created the bug and posted an incident report describing the serial number entropy issue, SSL.com’s review timeline, remediation steps, and planned revocations.
- Community commenter — Provided an updated, detailed remediation timeline including scans, replacement CA issuance, subscriber notification steps, and planned revocation/renewal actions.
- Fastly representative — Asked SSL.com to update the bug with results of its review of other CA/B Forum technical requirements and to state revocation plans and deadlines.
- Community commenter — Reported that the technical requirements review was initiated but not complete, and stated plans to revoke affected CA and end-entity TLS certificates by 2019-04-06 while reissuing and deprecating affected S/MIME issuing CAs.
- Community commenter — Posted another incident report update including a list of affected CA certificates and revocation statements.
- Fastly representative — Confirmed TLS certificates were revoked and thanked SSL.com for a remediation plan that included efforts to work with Primekey to improve EJBCA and plans for automated provisioning support.