← DarkMatter LLC cases
Bugzilla #1534535
Certificate Problem Report
QuoVadis / Siemens: Insufficient serial number entropy
RESOLVED
FIXED
DarkMatter LLC
AI Summary
The issue of insufficient serial number entropy was identified by Siemens during compliance scans in November 2017, leading to a proactive decision to increase the serial number length from 64 bits to 160 bits. This change was implemented on March 1, 2018, effectively stopping the issuance of certificates with the problematic configuration. A total of 35 certificates were identified with the issue, with the first issued on September 4, 2017, and the last on February 28, 2018. All problematic certificates have since been revoked.
Chronology
- Siemens CA first becomes aware of the potential issue.
- New configuration with increased serial number length goes live.
- Revocation of the last two problematic certificates confirmed.
Participants
Stephen Davidson
Rufus Buschart
External References
Similar Local Cases
QuoVadis / Freistaat Bayern: Non-BR-compliant Key Usage
QuoVadis: LLB insufficient Serial Number Entropy
QuoVadis: BR Error - san dns name starts with period
QuoVadis: IP in dnsName
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
QuoVadis: Incorrect EV businessCategory
QuoVadis: EV JOI Issue
QuoVadis: OCSP handling of Certificate Transparency Pre-certs