Kamu SM: Insufficient Serial Number Entropy
Kamu Sertifikasyon Merkezi (Kamu SM) disclosed that, during Mozilla Root Inclusion Request-related testing, it issued test certificates with serial numbers lower than 64 bits of entropy. Kamu SM stated it noticed this issue during its Mozilla root inclusion process and said its certificate issuance system was updated in 2017 to generate serial numbers with greater than 64-bit entropy. In its incident report, Kamu SM described that it renewed one “valid test SSL certificate” using the updated serial-number generation procedure, while it did not take action for the other two test certificates because one was revoked and the other was expired. After becoming aware of the EJBCA problem about DarkMatter concerns on 2019-02-26, Kamu SM informed its software developer team and had them check certificates issued under the specified subject, concluding that only the two mentioned test certificates were affected. Kamu SM also stated it continued issuing SSL certificates because it said no customer certificates were affected by the serial-number entropy issue. The bug was resolved as FIXED.
- Kamu SM issued three test certificates for the Mozilla Root Inclusion process with serial numbers lower than 64-bit entropy.
- Kamu SM updated its procedure for generating serial numbers to use greater than 64-bit entropy and renewed the valid test certificate accordingly.
- Kamu SM became aware of the EJBCA problem about DarkMatter concerns.
- Kamu SM’s team checked certificates issued under the specified subject and concluded only the two test certificates were affected.
- Kamu SM investigated and determined that two test certificates involved in the Mozilla root inclusion request were affected.
- Fastly representative — Wayne Thayer posted Kamu SM’s incident report describing the insufficient serial number entropy in Mozilla Root Inclusion Request test certificates, the 2017 remediation, and the conclusion that only two test certificates were affected.