GDCA: Insufficient Serial Number Entropy
This case concerns GDCA certificates with insufficient serial number entropy (serial number length less than 64 bits). GDCA said it became aware of the issue after noticing a discussion on mozilla.dev.security.policy about insufficient certificate serial numbers and then performing a self-assessment of the SSL/TLS certificates it issued. GDCA confirmed that certificates issued on or after December 1, 2017 by its upgraded issuance system exceeded 120 bits and were compliant, and it did not suspend current issuance. For certificates issued between September 30, 2016 and December 1, 2017, GDCA reported 283 affected SSL/TLS certificates, including 14 still valid with serial number length less than 64 bits. GDCA revoked 8 of the 14 valid certificates on March 19, 2019 and stated it expected to revoke the remaining 6 by March 31, 2019; it later reported that the additional 6 were revoked on March 29, 2019 and that all affected certificates were either revoked or expired as of that date. In response to questions about revocation delay, GDCA attributed the timing to customer revocation/replacement procedures for government institutions and said it would work to improve future efficiency while ensuring revocation meets BRs. The bug was resolved as FIXED, and a later comment indicated remediation was complete.
- GDCA upgraded its certificate issuance system and configured EJBCA serial number octet size to 16 to ensure serial number length exceeds 64 bits.
- Certificates with serial number length less than 64 bits were issued during this period (as later identified by GDCA).
- GDCA noticed the mozilla.dev.security.policy discussion about insufficient certificate serial numbers and began reviewing its issuance system.
- GDCA revoked 8 of the 14 still-valid affected certificates with serial number length less than 64 bits.
- GDCA revoked the remaining 6 affected certificates; GDCA reported all affected certificates were revoked or expired.
- A participant stated remediation appeared complete.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA described its self-assessment and actions, including confirming compliance for certificates issued after Dec 1, 2017, identifying 283 affected certificates from Sep 30, 2016 to Dec 1, 2017, revoking 8 valid certificates on Mar 19, 2019, and updating lint tools to prevent further issuance of serial numbers under 64 bits.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA reported it revoked the additional 6 affected certificates on March 29, 2019 and stated all affected certificates were revoked or expired as of that date.
- Community commenter — Ryan asked GDCA to explain the delay in revoking the additional 6 certificates and how future delays would be prevented.
- Global Digital Cybersecurity Authority Co., Ltd. (Formerly Guang Dong Certificate Authority (GDCA)) — GDCA explained the delay as due to time-consuming customer revocation/replacement procedures (especially for government institutions) and said it would improve communication efficiency and execute mandatory revocation when necessary.
- Community commenter — Ryan asked whether any further descriptions of steps taken were needed and noted it should be watched for future incidents.
- Fastly representative — A participant stated it appeared all questions had been answered and remediation was complete.