Actalis: Insufficient serial number entropy
Actalis identified an issue with insufficient entropy in the serial numbers of approximately 350,000 certificates issued between September 30, 2016, and March 6, 2019. The problem stemmed from the EJBCA software's unexpected behavior. Following the discovery on March 3, 2019, Actalis implemented a fix on March 6, ensuring all subsequent certificates had adequate entropy. The revocation of affected certificates began shortly after, with significant progress reported, although challenges arose due to the complexity of customer organizations and their internal processes. By August 1, 2019, Actalis confirmed that all impacted certificates had been revoked or expired.
- Actalis became aware of insufficient entropy in certificate serial numbers.
- Fix implemented to ensure certificates have adequate entropy.
- All impacted certificates confirmed revoked or expired.