PKIoverheid: KPN Insufficient Serial Number Entropy
The case involves PKIoverheid's disclosure of a compliance issue regarding insufficient entropy in the serial numbers of certificates issued by KPN. The issue was first identified on March 8, 2019, during a review of discussions in the Mozilla security policy mailing list. Following the identification, PKIoverheid initiated an investigation and determined that approximately 22,000 TLS certificates issued by KPN between September 30, 2016, and March 5, 2019, were potentially affected. A remediation plan was developed, which included revocation of the non-compliant certificates and transitioning to certificates with higher entropy. As of November 29, 2019, all affected certificates have been revoked, and the remediation efforts have been completed.
- PKIoverheid identifies insufficient entropy in KPN's serial numbers.
- All affected certificates have been revoked.
- Fastly representative — Jochem van den Berge posted the initial incident report regarding the serial number issue.
- Logius representative — Update on the investigation indicating potential impact on additional certificates.
- Logius representative — First actions of the remediation plan have been implemented.
- Logius representative — All certificates have been revoked.