← Entrust cases
Bugzilla #1536287 Certificate Misissuance

Entrust: AffirmTrust Issuing CA impacted by EJBCA serial number issue (63-bit serial numbers)

RESOLVED FIXED Entrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Entrust Datacard reported that its AffirmTrust issuing CAs were impacted by an EJBCA serial number issue where expected 64-bit serial numbers were actually only 63 bits long. Entrust said it became aware after an issue was reported against EJBCA and then investigated its own use of EJBCA, finding that only offline AffirmTrust root CAs used EJBCA with the problematic 64-bit configuration, resulting in issuing CA/intermediate certificates with serial numbers not meeting BR 7.1. Entrust confirmed that seven issuing CA/intermediate certificates were impacted and that one end-entity certificate with a 63-bit serial number was still active at the time of its initial report. Entrust stopped issuing TLS/SSL certificates with the problem by increasing serial number byte length to 128 bits via re-signing, and it re-signed the production intermediate certificates with 127-bit serial numbers, distributing updated certificates with all AffirmTrust issued certificates starting March 26, 2019. Entrust also revoked the non-production intermediate certificate and revoked additional intermediate certificates not used in production, and it revoked the affected end-entity certificate on March 22, 2019. The bug was marked RESOLVED with resolution FIXED, and Entrust later confirmed the re-signed intermediates were in production distribution and that planned activities were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 18:08 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.86 9 comments
Chronology
  1. News about the EJBCA serial number issue was reported and confirmed.
  2. Entrust Datacard internal investigation started.
  3. Operations confirmed seven AffirmTrust issuing CA/intermediate certificates were impacted and identified one active affected end-entity certificate.
  4. Production intermediate certificates were re-signed with 127-bit serial numbers; non-production and some unused intermediate certificates were revoked.
  5. The affected end-entity certificate was revoked.
  6. Updated intermediate certificates were scheduled to be distributed with all AffirmTrust issued certificates.
  7. Entrust confirmed re-signed intermediate certificates were in production distribution and activities were completed.
Thread Activity
  1. Entrustdatacard representative — Entrust described the EJBCA serial number issue affecting AffirmTrust issuing CAs, noting 63-bit serial numbers instead of expected 64-bit values.
  2. Titanous representative — Jonathan asked what Entrust meant by the issue being “reported,” referencing prior discussion and a Google email linking the behavior to EJBCA.
  3. Titanous representative — Jonathan questioned whether the “Trend Micro S2 CA” intermediate was included and asked about its analysis.
  4. Community commenter — Ryan asked why monitoring of mozilla.dev.security.policy was not performed and what steps would ensure compliance going forward.
  5. Entrustdatacard representative — Entrust responded that it monitored MDSP but did not initially connect the EJBCA configuration to its offline AffirmTrust roots, and it explained the status of the Trend Micro S2 CA and the affected end-entity certificate.
  6. Entrustdatacard representative — Entrust reported re-signing production intermediates with 127-bit serial numbers, distributing updated certificates starting March 26, revoking the non-production intermediate, revoking additional unused intermediates, and revoking the affected end-entity certificate.
  7. Entrustdatacard representative — Entrust confirmed the re-signed intermediates were in production distribution and that planned activities were completed, stating it was not planning to revoke the affected intermediates.
  8. Fastly representative — Wayne Thayer agreed that no MDSP posting was required by policy and stated he saw no remaining special issues or unanswered remediation actions.
Participants
Entrustdatacard representative Titanous representative Community commenter Fastly representative
Similar Local Cases
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 85% similar
Sectigo: invalid dnsName
#1567659 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-07-20 · Closed 2023-02-22 · 85% similar
Entrust: SHA-1 Issuance and other misissuance while testing
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1559376 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-06-14 · Closed 2023-02-22 · 84% similar
Entrust: Certificate Issued with Incorrect Country Code
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 84% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 83% similar
Entrust: IP in dnsName
#1538673 RESOLVED Certificate Misissuance Opened 2019-03-25 · Closed 2023-02-22 · 79% similar
Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action