← Autoridad de Certificacion Firmaprofesional cases
Bugzilla #1538638 Ca Certificate Compliance Self Reported Incident Revocation Issue

Firmaprofesional serial number entropy incident and certificate revocation follow-up

RESOLVED FIXED Autoridad de Certificacion Firmaprofesional
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Firmaprofesional opened this case to report that certificates issued by its "AC Firmaprofesional - INFRAESTRUCTURA" hierarchy had insufficient serial number entropy. The CA said it discovered the issue while reviewing Mozilla discussions about 64-bit serial number entropy and then investigated its systems. It reported that issuance of SSL certificates was stopped on 2019-03-16, fixes were deployed to increase serial numbers to 128 bits, and affected certificates were being reissued or revoked. Mozilla asked for clearer progress updates and confirmation of remediation, and Firmaprofesional provided periodic reports and a list of affected certificates. The CA later stated that all affected certificates had been revoked or expired, with two temporary exceptions for certificate pinning use cases, and then reported that the last certificate had been revoked. The bug was later marked resolved with remediation complete.

Model: gpt-5.4-mini Generated: 2026-06-13 18:09 UTC Revised: 2026-06-16 18:06 UTC Confidence: 0.98 32 comments
Chronology
  1. Firmaprofesional began investigating whether its certificate serial numbers had insufficient entropy.
  2. Firmaprofesional stopped issuing SSL certificates for the affected hierarchy.
  3. Firmaprofesional planned production deployment of the serial-number fix.
  4. Firmaprofesional said all affected certificates were revoked or expired except two temporary exceptions.
  5. Firmaprofesional said the last affected certificate had been revoked.
Thread Activity
  1. Isigma representative — The CA reported that certificates had only 63 bits of effective entropy, stopped issuance, and planned to increase serial numbers to 128 bits.
  2. Community commenter — Mozilla asked whether corrective actions had been deployed and what the status of the remaining certificate was.
  3. Isigma representative — The CA said the corrective actions were deployed, some affected certificates had been revoked, and all affected certificates would be revoked by 2019-07-31.
  4. Isigma representative — The CA attached an incident report, described progress on revocations, and said it would provide updates twice a week until completion.
  5. Community commenter — Mozilla asked about the Subscriber Agreement language and whether the CA's contract changes reflected a different interpretation of revocation obligations.
  6. Isigma representative — The CA said its Subscriber Agreement was legally valid and enforceable, but that it might be better to make some requirements more explicit to subscribers.
  7. Community commenter — Mozilla asked the CA to confirm that all 293 certificates would be revoked by 2019-07-31.
  8. Isigma representative — The CA confirmed the plan to revoke all 293 certificates by 2019-07-31.
  9. Isigma representative — The CA said all affected certificates had been revoked or expired except two certificates used for certificate pinning in mobile apps, and requested more time for those two.
  10. Isigma representative — The CA said one of the two remaining certificates had already been revoked.
  11. Isigma representative — The CA said the last certificate had been revoked.
  12. Fastly representative — Mozilla stated that all questions had been answered and remediation was complete.
Participants
Isigma representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1398240 RESOLVED Ca Certificate Compliance Incident Opened 2017-09-08 · Closed 2023-02-22 · 100% similar
Firmaprofesional: Non-BR-Compliant OCSP Responders
#1464335 RESOLVED Ca Certificate Compliance Opened 2018-05-25 · Closed 2023-02-22 · 97% similar
Firmaprofesional: Undisclosed Intermediate certificate SIGNE
#1717795 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2021-06-23 · Closed 2023-02-22 · 96% similar
Firmaprofesional: 2021 Audit Report Finding 3 out of 3
#1368171 RESOLVED Ca Certificate Compliance Incident Opened 2017-05-26 · Closed 2024-06-30 · 94% similar
Firmaprofesional: Non-audited, non-technically-constrained intermediate certificates
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 92% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1769240 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-13 · Closed 2023-02-22 · 91% similar
Firmaprofesional: 2022 - SSL certificates issued with wrong Organization ID number
#1649943 RESOLVED Ca Certificate Compliance Opened 2020-07-02 · Closed 2023-02-22 · 89% similar
Firmaprofesional: Incorrect OCSP Delegated Responder Certificate
#1771715 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2022-05-30 · Closed 2023-02-22 · 89% similar
Firmaprofesional: 2022 - StateorProvince field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action