Kamu SM: Insufficient Serial Number Entropy
The Government of Turkey's Kamu Sertifikasyon Merkezi (Kamu SM) reported an issue regarding insufficient entropy in the serial numbers of two test certificates issued during the Mozilla Root Inclusion Request process. The CA became aware of the problem on February 26, 2019, and confirmed that only the test certificates were affected, as their system had been updated in 2017 to ensure compliance with the required 64-bit entropy. No customer certificates were impacted, and the CA has continued issuing SSL certificates without interruption. The issue has been resolved, and the affected certificates were identified and documented.
- Kamu SM issued three test certificates.
- Kamu SM updated serial number generation to comply with 64-bit entropy.
- Kamu SM became aware of the EJBCA problem.
- Kamu SM informed the software development team about the issue.
- All issued certificates were checked; only test certificates were affected.