Buypass: Insufficient Serial Number Entropy
Buypass reported an incident involving two intermediate certificates issued on December 2, 2016 that were noncompliant with BR 7.1 due to insufficient entropy in the certificate serial numbers. Buypass stated it became aware of the issue after a March 18 publication on mozilla.dev.security.policy listing CAs noncompliant with the BR 7.1 entropy requirement, and it then sent a Pre-Incident Report on March 21. Buypass said its offline/airgapped Root CA system did not support inclusion of random values in certificate serial numbers at the time of the December 2016 ceremony, and that it had focused on implementing the entropy requirement for subscriber certificates instead. As remediation, Buypass issued two new intermediate certificates on March 25, 2019 with serial numbers compliant with BR 7.1, and distributed them to customers along with all new TLS certificates issued after that date. Buypass contacted customers and advised them to replace the affected intermediates, set May 15, 2019 as a deadline for customer replacement, and later decided not to revoke immediately due to customer and website vulnerability. Buypass revoked the two affected intermediate certificates on June 27, 2019, and a participant noted that remediation appeared completed. The bug is marked RESOLVED with resolution FIXED.
- Buypass issued two intermediate CA certificates with certificate serial numbers that did not meet the BR 7.1 entropy requirement.
- A list of CAs noncompliant with the BR 7.1 entropy requirement was published on mozilla.dev.security.policy, including Buypass root CAs.
- Buypass issued two replacement intermediate certificates with BR 7.1-compliant certificate serial number entropy.
- Buypass set May 15 as a deadline for customers to replace the affected intermediate certificates.
- Buypass revoked the two affected intermediate certificates.
- Fastly representative — Wayne Thayer posted Buypass’s incident report describing two noncompliant intermediate certificates and Buypass’s discovery, analysis, and remediation plan.
- Buypass — Mads Henriksveen stated Buypass contacted customers using its managed PKI solution and advised them to replace the intermediate certificates.
- Fastly representative — Wayne Thayer asked for the expected timing for having the affected intermediates replaced and then revoked.
- Community commenter — Ryan Sleevi asked what software the offline Root CA system runs and requested clarification about the lack of entropy support at the time of the December 2016 ceremony.
- Buypass — Mads Henriksveen said Buypass advised immediate replacement but had not set an explicit deadline yet, and planned to define a deadline and timeline.
- Buypass — Mads Henriksveen explained that Buypass’s offline Root CA application software was not updated with required entropy support before the December 2016 ceremony.
- Buypass — Mads Henriksveen set May 15 as a deadline for customer replacement and said revocation would follow shortly.
- Buypass — Mads Henriksveen reported that more than 90% of customers had updated by May 15 and that revocation would not be immediate, with a latest revocation date of end of June 2019.
- Buypass — Mads Henriksveen stated the two affected intermediate certificates were revoked on June 27, 2019.
- Fastly representative — Wayne Thayer commented that remediation appeared completed.