← GlobalSign nv-sa cases
Bugzilla #1535873 Certificate Problem Report

GlobalSign: AT&T Insufficient Serial Number Entropy

RESOLVED FIXED GlobalSign nv-sa
AI Summary

GlobalSign identified an issue with insufficient serial number entropy in certificates issued by AT&T, a customer using EJBCA with default settings. Following the discovery, AT&T was instructed to halt certificate issuance, update their configurations, and revoke affected certificates. A total of over 42,000 certificates were revoked, and AT&T upgraded their EJBCA to ensure compliance with the required serial number entropy. GlobalSign is in the process of closing down all subordinate CAs operated by third parties, with a target completion date set for August 2019.

Model: gpt-4o-mini Generated: 2026-06-13 18:08 UTC Confidence: 0.95
Chronology
  1. GlobalSign conducted a self-assessment on certificates issued from their data center.
  2. GlobalSign notified AT&T to stop issuance and update their configurations.
  3. AT&T upgraded EJBCA in test/dev to support 128-bit serial number entropy.
  4. AT&T confirmed the revocation of over 42,000 certificates.
  5. All misissued certificates with 63-bit serial numbers were revoked.
Participants
Wayne Thayer Doug Beattie
External References
Similar Local Cases
#1605372 RESOLVED Certificate Problem Report Opened 2019-12-20 · Closed 2023-02-22 · 57% similar
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#1536760 RESOLVED Certificate Problem Report Opened 2019-03-20 · Closed 2023-02-22 · 53% similar
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
#1532399 RESOLVED Certificate Problem Report Opened 2019-03-04 · Closed 2023-02-22 · 53% similar
TrustCor: Insufficient Serial Number Entropy
#1539190 RESOLVED Certificate Problem Report Opened 2019-03-26 · Closed 2023-02-22 · 52% similar
Kamu SM: Insufficient Serial Number Entropy
#1534147 RESOLVED Certificate Problem Report Opened 2019-03-10 · Closed 2023-02-22 · 52% similar
SSL.com: Insufficient serial number entropy
#1304089 RESOLVED Certificate Problem Report Opened 2016-09-20 · Closed 2022-11-14 · 52% similar
Bug in GlobalSign Certificate Centre not populating EKUs in 68 SSL certificates
#1539307 RESOLVED Certificate Problem Report Opened 2019-03-27 · Closed 2023-02-22 · 51% similar
Buypass: Insufficient Serial Number Entropy
#1353833 RESOLVED Certificate Problem Report Opened 2017-04-05 · Closed 2023-02-22 · 51% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action