Firmaprofesional serial number entropy incident and certificate revocation follow-up
Firmaprofesional opened this case to report that certificates issued by its "AC Firmaprofesional - INFRAESTRUCTURA" hierarchy had insufficient serial number entropy. The CA said it discovered the issue while reviewing Mozilla discussions about 64-bit serial number entropy and then investigated its systems. It reported that issuance of SSL certificates was stopped on 2019-03-16, fixes were deployed to increase serial numbers to 128 bits, and affected certificates were being reissued or revoked. Mozilla asked for clearer progress updates and confirmation of remediation, and Firmaprofesional provided periodic reports and a list of affected certificates. The CA later stated that all affected certificates had been revoked or expired, with two temporary exceptions for certificate pinning use cases, and then reported that the last certificate had been revoked. The bug was later marked resolved with remediation complete.
- Firmaprofesional began investigating whether its certificate serial numbers had insufficient entropy.
- Firmaprofesional stopped issuing SSL certificates for the affected hierarchy.
- Firmaprofesional planned production deployment of the serial-number fix.
- Firmaprofesional said all affected certificates were revoked or expired except two temporary exceptions.
- Firmaprofesional said the last affected certificate had been revoked.
- Isigma representative — The CA reported that certificates had only 63 bits of effective entropy, stopped issuance, and planned to increase serial numbers to 128 bits.
- Community commenter — Mozilla asked whether corrective actions had been deployed and what the status of the remaining certificate was.
- Isigma representative — The CA said the corrective actions were deployed, some affected certificates had been revoked, and all affected certificates would be revoked by 2019-07-31.
- Isigma representative — The CA attached an incident report, described progress on revocations, and said it would provide updates twice a week until completion.
- Community commenter — Mozilla asked about the Subscriber Agreement language and whether the CA's contract changes reflected a different interpretation of revocation obligations.
- Isigma representative — The CA said its Subscriber Agreement was legally valid and enforceable, but that it might be better to make some requirements more explicit to subscribers.
- Community commenter — Mozilla asked the CA to confirm that all 293 certificates would be revoked by 2019-07-31.
- Isigma representative — The CA confirmed the plan to revoke all 293 certificates by 2019-07-31.
- Isigma representative — The CA said all affected certificates had been revoked or expired except two certificates used for certificate pinning in mobile apps, and requested more time for those two.
- Isigma representative — The CA said one of the two remaining certificates had already been revoked.
- Isigma representative — The CA said the last certificate had been revoked.
- Fastly representative — Mozilla stated that all questions had been answered and remediation was complete.