← GlobalSign nv-sa cases
Bugzilla #1536760
Certificate Problem Report
GlobalSign: Virginia Tech Insufficient Serial Number Entropy
RESOLVED
FIXED
GlobalSign nv-sa
AI Summary
GlobalSign reported an issue regarding insufficient serial number entropy for certificates issued to Virginia Tech. The CA issued 63-bit serial numbers instead of the required 64 bits from September 30, 2016, to April 26, 2018. Upon receiving a disclosure report, GlobalSign ceased issuing certificates from this CA and initiated a revocation process. By April 2019, all non-expired certificates with the problematic serial numbers were successfully revoked.
Chronology
- GlobalSign researched VT issuance and identified non-compliance.
- GlobalSign stopped issuing certificates from the affected CA.
- All non-expired certificates with 63-bit serial numbers were revoked.
Participants
douglas.beattie@gmail.com
ryan.sleevi@gmail.com
External References
Similar Local Cases
GlobalSign: SPKI lacks explicit NULL parameter,
GlobalSign: SSL Certificates with US country code and invalid State/Prov
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates
GlobalSign: OCSP Status HTTP 530
GlobalSign: AT&T Insufficient Serial Number Entropy
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
GDCA: Insufficient Serial Number Entropy
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy