← HARICA cases
Bugzilla #1535509 Incident Certificate Misissuance Revocation Issue

HARICA: Insufficient serial number entropy

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns HARICA’s discovery and disclosure of a compliance issue with certificate serial number entropy. HARICA reported that Mozilla-dev-security-policy discussion revealed that EJBCA’s default serial number configuration effectively produced serial numbers with 63 truly random bits because the serial number must be positive, making the first bit zero. HARICA stated it monitored the discussion and determined its EJBCA configuration was using the default serial number size, leading to issuance of non-compliant serial numbers between 2018-05-04 and 2019-03-05. HARICA conducted a full certificate database scan and reported 461 SSL/TLS, 4157 S/MIME, and 15 CA certificates (unexpired and unrevoked) with improper serial numbers, plus additional affected certificates issued from a CA with improper serial numbers. HARICA planned revocations for the problematic SSL/TLS certificates by March 16, 2019 and for CA certificates capable of issuing SSL/TLS certificates by March 18, 2019, and later reported that all scheduled revocations were performed as planned. The bug was resolved as FIXED, and a participant noted that remediation appeared complete.

Model: gpt-5.4-nano Generated: 2026-06-13 18:07 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.90 9 comments
Chronology
  1. HARICA began issuing certificates with non-compliant serial number entropy after migrating to EJBCA.
  2. The period of issuance with non-compliant serial number entropy ended.
  3. HARICA disclosed the incident to Mozilla and provided an incident report describing the affected certificates and planned revocations.
  4. Planned revocation date for problematic SSL/TLS certificates.
  5. Planned revocation date for CA certificates capable of issuing SSL/TLS certificates.
  6. HARICA submitted a final incident report stating scheduled revocations were performed as planned.
Thread Activity
  1. HARICA — HARICA described the incident, explaining how EJBCA’s default serial number configuration resulted in effectively 63 bits of entropy and listing the affected certificate counts and planned revocation timelines.
  2. HARICA — HARICA corrected the incident report executive summary regarding the serial number bits used in its earlier custom CA software.
  3. HARICA — HARICA stated that all scheduled revocations were performed as planned and that the final report includes this information.
  4. Fastly representative — A participant commented that remediation appeared complete.
Participants
HARICA Fastly representative
External References
Similar Local Cases
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 100% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 89% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 88% similar
HARICA: 3 EV TLS Certificates without L or ST
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 88% similar
HARICA: Certificates with invalid policy tree
#1872374 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-12-29 · Closed 2026-06-10 · 87% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 87% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1580393 RESOLVED Incident Self Reported Incident Opened 2019-09-11 · Closed 2022-11-14 · 82% similar
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
#2056668 UNCONFIRMED Policy Document Issue Incident Self Reported Incident Certificate Misissuance Opened 2026-07-21 Still Open · 78% similar
HARICA: Issuance of Server TLS Certificates without AIA OCSP URI against CP/CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action