← SECOM Trust Systems CO., LTD. cases
Bugzilla #1539358
Certificate Problem Report
SECOM: Insufficient Serial Number Entropy
RESOLVED
FIXED
SECOM Trust Systems CO., LTD.
AI Summary
SECOM Trust Systems identified an issue with insufficient entropy in the serial numbers of their certificates, first noted on March 7, 2019. The CA did not stop issuing certificates while investigating the problem, which involved multiple systems and required careful migration. The resolution process was complicated due to the need to coordinate with customers and ensure compliance across all issuing CAs. By May 13, 2019, SECOM reported that remediation for all affected CAs was completed.
Chronology
- Issue first identified in Mozilla mailing list.
- Resolution for several intermediate CAs completed.
- Resolution for the remaining CAs completed.
Participants
Hisashi Kamo
Ryan Sleevi
W. Thayer
External References
Similar Local Cases
SECOM: certificate for which “OU=-”
SECOM: Incorrect OCSP Delegated Responder Certificate
SECOM: certificate for which “L” and “ST” not set
SECOM: Outdated audit statements for intermediate certificates
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
SECOM: Ambiguity on KeyUsage with ECC public key
E-Tugra: Insufficient serial number entropy
SECOM: Non-BR-Compliant OCSP Responders