Actalis incident report: insufficient serial number entropy and resulting certificate revocations
Actalis disclosed that it discovered a problem with insufficient entropy in certificate serial numbers and began investigating the impact on 2019-03-03. The CA said the root cause was unexpected and undocumented behavior in EJBCA, and that it fixed the issue on 2019-03-06 so newly issued certificates would use longer serial numbers. Actalis reported that roughly 350,000 certificates were issued with the problem, later refining the impacted set to 411,333 certificates, with a large number still active at the time of reporting. The thread then focused on revocation progress, with Actalis providing periodic updates on reissuance and revocation rates across DV, OV, and EV certificates. Mozilla requested clearer timelines and more detail about the revocation delays and future prevention measures. By August 2019, Actalis said all involved certificates had been revoked or expired, and Mozilla noted that a separate bug had been opened for the delayed revocation issue.
- Actalis became aware of insufficient entropy in certificate serial numbers and started investigating the impact.
- Actalis fixed the serial-number generation problem and began issuing certificates with longer serial numbers.
- Actalis reported that 411,333 certificates were impacted, with 249,627 still active at that time.
- Actalis said all involved certificates had been revoked or expired.
- Staff representative — Actalis opened the bug and said it had found about 230,000 active certificates with 63 bits of entropy and had implemented a fix on 2019-03-06.
- Community commenter — Mozilla asked for details on the impacted certificates and requested a preliminary incident report and clearer timelines.
- Staff representative — Actalis provided a fuller incident report, including a timeline, impact summary, and planned revocation and prevention steps.
- Staff representative — Actalis updated the impacted-certificate counts and reported progress on DV, OV, and EV revocations.
- Staff representative — Actalis said it had made mistakes in communication and operations, changed management and escalation, and committed to revoking the remaining certificates by 2019-07-31.
- Staff representative — Actalis said it would close this incident and open a new one focused on failure to revoke within BR requirements.
- Staff representative — Actalis posted the new incident bug 1572638.
- Fastly representative — Mozilla said that, with the separate delayed-revocation bug opened, the questions in this bug had been answered and remediation was complete.