ACCV: Insufficient serial number entropy
The Autoritat de Certificació de la Comunitat Valenciana (ACCV) identified a compliance issue regarding insufficient entropy in the serial numbers of approximately 1,800 certificates. The CA discovered this problem through discussions in the Mozilla developer community and took immediate action to investigate and rectify the issue. They confirmed the incorrect generation of serial numbers and implemented a patch to ensure compliance with the 64-bit requirement. ACCV communicated with affected users, initiated certificate replacements, and established a revocation mechanism. As of July 22, 2019, all affected certificates were successfully replaced, and the CA has committed to improving their processes to prevent future incidents.
- ACCV began researching the insufficient entropy issue.
- All remaining affected certificates were replaced.
- Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV reported the discovery of insufficient serial number entropy.
- Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV attached a list of affected certificates.
- Community commenter — Request for a status update on the remediation efforts.
- Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV confirmed that 97.9% of certificates had been replaced.
- Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) — ACCV confirmed that the remaining 25 certificates had been replaced.
- Fastly representative — Confirmation that remediation is complete.