← Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) cases
Bugzilla #1538673 Certificate Misissuance

Consorci AOC: EC-SectorPublic insufficient serial number entropy

RESOLVED FIXED Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that Consorci AOC issued SSL certificates with insufficient serial number entropy for certificates under the "CN=EC-SectorPublic" hierarchy. Consorci AOC said it became aware of the issue via the mozilla.dev.security.policy (m.d.s.p.) group on 2019-03-15, and that it continued issuing certificates while the discussion on severity was ongoing. On 2019-03-22 15:00 CET, Consorci AOC began investigating possible violation of BR v.1.6.3 §7.1, and on 2019-03-22 16:00 CET it identified that its systems were affected and stopped accepting new issuance requests. Consorci AOC stated that it updated its TEST environment to issue 128-bit serial number certificates and planned to update PRODUCTION and resume issuance. A Mozilla participant later stated that it appears remediation has been completed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:09 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.86 9 comments
Chronology
  1. Consorci AOC became aware via the mozilla.dev.security.policy group about 64-bit entropy for serial number generation.
  2. Consorci AOC investigated and identified affected systems for CN=EC-SectorPublic and stopped accepting new issuance requests.
  3. Consorci AOC updated its TEST environment to use 128-bit serial numbers and planned a PRODUCTION update.
  4. A Mozilla participant indicated remediation appears to be completed.
Thread Activity
  1. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Francesc Ferrer reported that certificates had 63 bits of entropy instead of the expected at least 64 bits, described the investigation timeline, and stated TEST was updated to issue 128-bit serial numbers with a planned PRODUCTION update.
  2. Community commenter — Ryan Sleevi asked why Consorci AOC’s investigation and disclosure were delayed and requested more thorough analysis of EJBCA default configuration examination and future timeliness steps.
  3. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Francesc Ferrer responded that Consorci AOC viewed the issue as a compliance matter, described checks of EJBCA default settings and TEST/PRODUCTION, and stated PRODUCTION would be updated with 128-bit serial numbers.
  4. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Francesc Ferrer clarified that they first became aware on 2019-03-15, continued issuing while severity was discussed, and provided additional details including a stopped-acceptance date and a CT reference.
  5. Community commenter — Ryan Sleevi asked whether Consorci AOC received notice from EJBCA (citing another bug) and pressed for explanation of the delay and monitoring gaps.
  6. Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) — Francesc Ferrer said notice never arrived from PrimeKey, identified two root causes (lack of people monitoring mdsp and an incorrect incident management procedure), and listed improvements including increased mdsp monitoring resources and incident procedure enforcement.
  7. Fastly representative — W. Thayer stated that it appears all remediation has been completed.
Participants
Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 87% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1536287 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 79% similar
Entrust: AffirmTrust Issuing CA Impacted by EJBCA Serial Number Issue
#1527423 RESOLVED Certificate Misissuance Opened 2019-02-12 · Closed 2023-02-22 · 78% similar
DigiCert: P-384,ecdsa-with-SHA512 Certificates
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 78% similar
D-TRUST: Non-BR-Compliant Certificate Issuance
#1462797 RESOLVED Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 77% similar
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1550575 RESOLVED Certificate Misissuance Opened 2019-05-09 · Closed 2023-02-22 · 77% similar
Asseco DS / Certum: commonName not from subjectAltName entries
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 77% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 76% similar
Sectigo: invalid dnsName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action