Entrust: AffirmTrust Issuing CA impacted by EJBCA serial number issue (63-bit serial numbers)
Entrust Datacard reported that its AffirmTrust issuing CAs were impacted by an EJBCA serial number issue where expected 64-bit serial numbers were actually only 63 bits long. Entrust said it became aware after an issue was reported against EJBCA and then investigated its own use of EJBCA, finding that only offline AffirmTrust root CAs used EJBCA with the problematic 64-bit configuration, resulting in issuing CA/intermediate certificates with serial numbers not meeting BR 7.1. Entrust confirmed that seven issuing CA/intermediate certificates were impacted and that one end-entity certificate with a 63-bit serial number was still active at the time of its initial report. Entrust stopped issuing TLS/SSL certificates with the problem by increasing serial number byte length to 128 bits via re-signing, and it re-signed the production intermediate certificates with 127-bit serial numbers, distributing updated certificates with all AffirmTrust issued certificates starting March 26, 2019. Entrust also revoked the non-production intermediate certificate and revoked additional intermediate certificates not used in production, and it revoked the affected end-entity certificate on March 22, 2019. The bug was marked RESOLVED with resolution FIXED, and Entrust later confirmed the re-signed intermediates were in production distribution and that planned activities were completed.
- News about the EJBCA serial number issue was reported and confirmed.
- Entrust Datacard internal investigation started.
- Operations confirmed seven AffirmTrust issuing CA/intermediate certificates were impacted and identified one active affected end-entity certificate.
- Production intermediate certificates were re-signed with 127-bit serial numbers; non-production and some unused intermediate certificates were revoked.
- The affected end-entity certificate was revoked.
- Updated intermediate certificates were scheduled to be distributed with all AffirmTrust issued certificates.
- Entrust confirmed re-signed intermediate certificates were in production distribution and activities were completed.
- Entrustdatacard representative — Entrust described the EJBCA serial number issue affecting AffirmTrust issuing CAs, noting 63-bit serial numbers instead of expected 64-bit values.
- Titanous representative — Jonathan asked what Entrust meant by the issue being “reported,” referencing prior discussion and a Google email linking the behavior to EJBCA.
- Titanous representative — Jonathan questioned whether the “Trend Micro S2 CA” intermediate was included and asked about its analysis.
- Community commenter — Ryan asked why monitoring of mozilla.dev.security.policy was not performed and what steps would ensure compliance going forward.
- Entrustdatacard representative — Entrust responded that it monitored MDSP but did not initially connect the EJBCA configuration to its offline AffirmTrust roots, and it explained the status of the Trend Micro S2 CA and the affected end-entity certificate.
- Entrustdatacard representative — Entrust reported re-signing production intermediates with 127-bit serial numbers, distributing updated certificates starting March 26, revoking the non-production intermediate, revoking additional unused intermediates, and revoking the affected end-entity certificate.
- Entrustdatacard representative — Entrust confirmed the re-signed intermediates were in production distribution and that planned activities were completed, stating it was not planning to revoke the affected intermediates.
- Fastly representative — Wayne Thayer agreed that no MDSP posting was required by policy and stated he saw no remaining special issues or unanswered remediation actions.