← Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) cases
Bugzilla #1538673 Certificate Problem Report

Consorci AOC: EC-SECTORPUBLIC insufficient serial number entropy

RESOLVED FIXED Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)
AI Summary

Consorci AOC identified an issue with SSL certificates issued under the 'CN=EC-SectorPublic' where the serial number entropy was insufficient, at 63 bits instead of the required 64 bits. The CA became aware of the problem through discussions on mozilla.dev.security.policy and took immediate action to stop issuing certificates. They have since updated their systems to ensure compliance with Baseline Requirements by configuring serial numbers to 128 bits. The incident raised concerns about the timeliness of their response and monitoring practices, leading to improvements in their incident management procedures.

Model: gpt-4o-mini Generated: 2026-06-13 18:09 UTC Confidence: 0.90
Chronology
  1. Identified issue with insufficient serial number entropy.
  2. Stopped issuance of affected SSL certificates.
  3. Implemented improvements in monitoring and incident management.
Participants
Francesc Ferrer Ryan Sleevi
External References
Similar Local Cases
#1390988 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 68% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1467110 RESOLVED Certificate Problem Report Opened 2018-06-06 · Closed 2024-05-09 · 59% similar
Consorci AOC: OCSP responding good for non-issued certs by Consorci AOC root already solved
#1428832 RESOLVED Certificate Problem Report Opened 2018-01-08 · Closed 2023-02-22 · 56% similar
Consorci AOC: Problem reporting mechanism for Consorci AOC points to URL with invalid cert
#1450805 RESOLVED Certificate Problem Report Opened 2018-04-02 · Closed 2022-11-14 · 56% similar
Add Consorci AOC "old" hierarchy to OneCRL
#1542302 RESOLVED Certificate Problem Report Opened 2019-04-05 · Closed 2023-02-22 · 53% similar
E-Tugra: Insufficient serial number entropy
#1533774 RESOLVED Certificate Problem Report Opened 2019-03-08 · Closed 2023-02-22 · 53% similar
GoDaddy: Insufficient serial number entropy
#1596744 RESOLVED Certificate Problem Report Opened 2019-11-15 · Closed 2024-06-30 · 52% similar
Izenpe: Intermediate CA certificates not listed in audit report
#1539358 RESOLVED Certificate Problem Report Opened 2019-03-27 · Closed 2023-02-22 · 52% similar
SECOM: Insufficient Serial Number Entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action