MULTICERT SSL CA 001: insufficient serial number entropy and remediation
Multicert disclosed that certificates issued by its MULTICERT SSL Certification Authority 001 had only 63 bits of effective serial number entropy, which it said violated BR v1.6.3 §7.1. The company said it learned of the issue while reviewing ongoing discussions on mozilla.dev.security.policy and began investigating on 2019-03-11. It stopped certificate issuance, developed a fix, and resumed issuance after deploying the change on 2019-03-12. The thread then focused on replacement and revocation of affected certificates, including questions about whether revocation was being handled within the expected timeframes. Multicert later reported staged revocations, accelerated its replacement plan, and ultimately stated that all outstanding certificates had been revoked. The bug was resolved as FIXED.
- Multicert identified that certificates from MULTICERT SSL CA 001 were affected by insufficient serial number entropy.
- Multicert stopped issuing affected certificates and began remediation.
- Multicert deployed the fix and resumed certificate issuance.
- Multicert reported batch revocation completed for the affected certificates.
- Multicert confirmed that all outstanding affected certificates had been revoked.
- MULTICERT — Multicert reported the entropy issue, said it had stopped issuance, and described its initial remediation plan.
- MULTICERT — Multicert said the fix had been deployed in production and issuance had resumed.
- Community commenter — Ryan Sleevi asked whether the affected certificates had been revoked and noted Mozilla's revocation expectations.
- MULTICERT — Multicert provided an update with revocation counts and a replacement plan.
- MULTICERT — Multicert said it would accelerate replacement and have all affected certificates replaced or revoked by July 1.
- MULTICERT — Multicert reported revocation was planned for that night and identified a few special cases involving mobile banking apps.
- MULTICERT — Multicert said batch revocation was completed, with one further exception pending.
- Community commenter — Ryan Sleevi asked for confirmation that all outstanding certificates had been revoked.
- MULTICERT — Multicert confirmed all outstanding certificates were revoked, including the remaining special cases.
- Fastly representative — W. Thayer said all questions had been answered and remediation was complete.