← Actalis cases
Bugzilla #1534295 Vulnerability Disclosure

Actalis incident report: insufficient serial number entropy and resulting certificate revocations

RESOLVED FIXED Actalis
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Actalis disclosed that it discovered a problem with insufficient entropy in certificate serial numbers and began investigating the impact on 2019-03-03. The CA said the root cause was unexpected and undocumented behavior in EJBCA, and that it fixed the issue on 2019-03-06 so newly issued certificates would use longer serial numbers. Actalis reported that roughly 350,000 certificates were issued with the problem, later refining the impacted set to 411,333 certificates, with a large number still active at the time of reporting. The thread then focused on revocation progress, with Actalis providing periodic updates on reissuance and revocation rates across DV, OV, and EV certificates. Mozilla requested clearer timelines and more detail about the revocation delays and future prevention measures. By August 2019, Actalis said all involved certificates had been revoked or expired, and Mozilla noted that a separate bug had been opened for the delayed revocation issue.

Model: gpt-5.4-mini Generated: 2026-06-13 18:07 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.97 31 comments
Chronology
  1. Actalis became aware of insufficient entropy in certificate serial numbers and started investigating the impact.
  2. Actalis fixed the serial-number generation problem and began issuing certificates with longer serial numbers.
  3. Actalis reported that 411,333 certificates were impacted, with 249,627 still active at that time.
  4. Actalis said all involved certificates had been revoked or expired.
Thread Activity
  1. Staff representative — Actalis opened the bug and said it had found about 230,000 active certificates with 63 bits of entropy and had implemented a fix on 2019-03-06.
  2. Community commenter — Mozilla asked for details on the impacted certificates and requested a preliminary incident report and clearer timelines.
  3. Staff representative — Actalis provided a fuller incident report, including a timeline, impact summary, and planned revocation and prevention steps.
  4. Staff representative — Actalis updated the impacted-certificate counts and reported progress on DV, OV, and EV revocations.
  5. Staff representative — Actalis said it had made mistakes in communication and operations, changed management and escalation, and committed to revoking the remaining certificates by 2019-07-31.
  6. Staff representative — Actalis said it would close this incident and open a new one focused on failure to revoke within BR requirements.
  7. Staff representative — Actalis posted the new incident bug 1572638.
  8. Fastly representative — Mozilla said that, with the separate delayed-revocation bug opened, the questions in this bug had been answered and remediation was complete.
Participants
Staff representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1539190 RESOLVED Self Reported Incident Vulnerability Disclosure Opened 2019-03-26 · Closed 2023-02-22 · 70% similar
Kamu SM: Insufficient Serial Number Entropy
#1586787 RESOLVED Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 68% similar
Actalis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1648997 RESOLVED Certificate Misissuance Opened 2020-06-28 · Closed 2023-02-22 · 61% similar
Actalis: inaccurate value in stateOrProvinceName
#1390974 RESOLVED Certificate Misissuance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 60% similar
Actalis: Non-BR-Compliant Certificate Issuance
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 60% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements
#1955721 RESOLVED Self Reported Incident Vulnerability Disclosure Opened 2025-03-21 · Closed 2025-06-10 · 57% similar
Let's Encrypt: Failure to Document Analysis of Detected Vulnerabilities
#1824319 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-03-24 · Closed 2023-07-20 · 53% similar
Actalis: pre-certificates with “certificateHold” as the revocation reason
#1914419 RESOLVED Certificate Misissuance Opened 2024-08-22 · Closed 2025-02-04 · 52% similar
Actalis: Use of CRLReason Code in Certificate Revocation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action