← SSL.com cases
Bugzilla #1534147 Certificate Misissuance

SSL.com: Insufficient serial number entropy

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that SSL.com, which uses EJBCA internally, identified an issue affecting certificate serial number generation that could violate CA/B Forum Baseline Requirements (BR 7.1). SSL.com said it became aware of the problem by following discussions on mozilla.dev.security.policy and initiated a review on 2019-03-05, confirming the issue existed in SSL.com certificates. SSL.com deployed a correction to production systems on 2019-03-05 and resumed certificate issuance with serials meeting the requirements. SSL.com also initiated a plan to revoke affected certificates, including a timeline to revoke affected CA and end-entity TLS certificates by 2019-04-06, and to handle affected S/MIME certificates differently based on its interpretation of requirements. SSL.com stated that it would revoke CA and end-entity TLS certificates affected by 2019-04-06, and that it agreed with an interpretation for S/MIME certificates and would not revoke certificates not used in the WebPKI and not under the CA/B Forum Baseline Requirements; it said it reissued affected S/MIME issuing CAs and began deprecating the old ones. In the thread, the reporter later confirmed that all TLS certificates had been revoked, and described remediation efforts beyond the immediate issue.

Model: gpt-5.4-nano Generated: 2026-06-13 18:06 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.62 8 comments
Chronology
  1. SSL.com initiated a review of an EJBCA serial number entropy issue and deployed a correction to production systems.
  2. SSL.com initiated a plan to revoke all certificates affected by the serial number issue.
  3. SSL.com performed a key ceremony to issue replacement CA certificates.
  4. SSL.com resumed issuance of new end-entity certificates using replacement CA certificates and prepared subscriber notifications.
  5. SSL.com revoked affected TLS end-entity certificates per the remediation timeline.
  6. SSL.com approved a final incident report by management.
Thread Activity
  1. Fastly representative — Created the bug and posted an incident report describing the serial number entropy issue, SSL.com’s review timeline, remediation steps, and planned revocations.
  2. Community commenter — Provided an updated, detailed remediation timeline including scans, replacement CA issuance, subscriber notification steps, and planned revocation/renewal actions.
  3. Fastly representative — Asked SSL.com to update the bug with results of its review of other CA/B Forum technical requirements and to state revocation plans and deadlines.
  4. Community commenter — Reported that the technical requirements review was initiated but not complete, and stated plans to revoke affected CA and end-entity TLS certificates by 2019-04-06 while reissuing and deprecating affected S/MIME issuing CAs.
  5. Community commenter — Posted another incident report update including a list of affected CA certificates and revocation statements.
  6. Fastly representative — Confirmed TLS certificates were revoked and thanked SSL.com for a remediation plan that included efforts to work with Primekey to improve EJBCA and plans for automated provisioning support.
Participants
Fastly representative Community commenter
Similar Local Cases
#1719916 RESOLVED Certificate Misissuance Opened 2021-07-09 · Closed 2023-02-22 · 46% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1538673 RESOLVED Certificate Misissuance Opened 2019-03-25 · Closed 2023-02-22 · 38% similar
Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy
#1534145 RESOLVED Certificate Misissuance Opened 2019-03-10 · Closed 2023-02-22 · 35% similar
SSL.com: P-384 curve / ecdsa-with-SHA256 certificates
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 35% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1485413 RESOLVED Ca Certificate Compliance Opened 2018-08-22 · Closed 2023-02-22 · 35% similar
Certigna: Issuance without respecting CAA records

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action