← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1538638
Certificate Problem Report
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
RESOLVED
FIXED
Autoridad de Certificacion Firmaprofesional
AI Summary
Firmaprofesional identified an issue with SSL certificates issued by their AC Firmaprofesional - INFRAESTRUCTURA, which had insufficient serial number entropy of 63 bits instead of the required 64 bits. The problem was first noted on March 15, 2019, leading to an immediate halt in certificate issuance and the initiation of corrective measures. By July 31, 2019, all affected certificates had been revoked or expired, except for two critical certificates that were later revoked in August 2019. The CA has since updated its systems to ensure compliance with entropy requirements.
Chronology
- Identified issue with insufficient serial number entropy.
- Stopped issuance of SSL certificates.
- All affected certificates revoked or expired.
- Last affected certificate revoked.
Participants
chemalogo@isigma.es
ryan.sleevi@gmail.com
wthayer@fastly.com
External References
Similar Local Cases
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Firmaprofesional: Undisclosed Intermediate certificate SDS
Add several ICAs of Firmaprofesional to OneCRL
Firmaprofesional: incorrect reserved CA/B Forum OIDs in certificates
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
Atos: Insufficient Serial Number Entropy
GDCA: Insufficient Serial Number Entropy
GlobalSign: SPKI lacks explicit NULL parameter,