← Buypass cases
Bugzilla #1539307
Certificate Problem Report
Buypass: Insufficient Serial Number Entropy
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported an incident involving two intermediate certificates issued in December 2016 that did not comply with the entropy requirements outlined in BR 7.1. The issue was identified following a discussion on the mozilla.dev.security.policy list, leading to immediate actions including the issuance of new compliant certificates and communication with affected customers. The problematic certificates were eventually revoked on June 27, 2019, after a majority of customers had updated to the new certificates.
Chronology
- Buypass became aware of noncompliance with entropy requirements.
- New compliant intermediate certificates were issued.
- Deadline set for customers to replace affected certificates.
- The two affected intermediate certificates were revoked.
Participants
Wayne Thayer
Mads Henriksveen
External References
Similar Local Cases
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: Intermediate certificates not listed in audit reports
Buypass: intermediate certificates not revoked within BR time period
Buypass: TLS certificates with incorrect Subject attribute order
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
Buypass: Using an external DNS Resolver for DNS lookups