← HARICA cases
Bugzilla #1535509 Certificate Problem Report

HARICA: Insufficient serial number entropy

RESOLVED FIXED HARICA
AI Summary

HARICA identified a compliance issue regarding the entropy of serial numbers in certificates issued between May 4, 2018, and March 5, 2019. The CA software used, EJBCA, was configured to produce serial numbers with only 63 bits of entropy instead of the required 64 bits. This led to the issuance of 461 SSL/TLS certificates and 4157 S/MIME certificates with non-compliant serial numbers. Mitigation measures have been identified, and revocation of the affected certificates was scheduled as per the Baseline Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 18:07 UTC Confidence: 0.95
Chronology
  1. Incident reported and investigation initiated.
  2. Planned revocation of problematic SSL/TLS certificates.
  3. Planned revocation of problematic CA certificates.
  4. Remediation confirmed as complete.
Participants
Dimitris Zacharopoulos W. Thayer
External References
Similar Local Cases
#1580393 RESOLVED Certificate Problem Report Opened 2019-09-11 · Closed 2022-11-14 · 63% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1699796 RESOLVED Certificate Problem Report Opened 2021-03-19 · Closed 2023-02-22 · 60% similar
HARICA: Certificates with invalid policy tree
#1649945 RESOLVED Certificate Problem Report Opened 2020-07-02 · Closed 2023-02-22 · 59% similar
HARICA: Incorrect OCSP Delegated Responder Certificate
#1878106 RESOLVED Certificate Problem Report Opened 2024-02-01 · Closed 2024-03-08 · 58% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1942130 RESOLVED Certificate Problem Report Opened 2025-01-16 · Closed 2025-05-01 · 57% similar
HARICA: S/MIME certificate issuance without proper validation
#1535772 RESOLVED Certificate Problem Report Opened 2019-03-15 · Closed 2023-02-22 · 57% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1963629 RESOLVED Certificate Problem Report Opened 2025-04-30 · Closed 2025-07-08 · 56% similar
HARICA: One of the two Certificate Problem Report email aliases not working
#2029643 RESOLVED Certificate Problem Report Opened 2026-04-06 · Closed 2026-05-22 · 53% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action