QuoVadis: LLB insufficient Serial Number Entropy
The case concerns QuoVadis-related S/MIME certificates issued by LLB (an external subCA signed by QuoVadis) that had insufficient serial number entropy. LLB was informed by QuoVadis on March 8, 2019 about possible issues with 64-bit entropy in certificate serial numbers. In response, LLB stopped issuing certificates and changed its configuration to use 20-octet serials, after analyzing affected certificates with an external consultant. LLB stated that certificates were only issued to internal employees and that it intended to revoke and reissue the affected certificates. LLB later confirmed that, as of June 8, the last of the affected S/MIME certificates had been revoked and that remediation was complete. The bug was marked RESOLVED with resolution FIXED, and other participants noted that remediation appeared completed but asked that the bug not be closed without CA Certificates Module input.
- LLB was informed by QuoVadis about possible issues with 64-bit entropy in certificate serial numbers.
- LLB received a report from an external consultant about affected CA and certificates.
- LLB reported back to QuoVadis and continued discussion.
- LLB revoked the last of the affected S/MIME certificates and considered remediation complete.
- DigiCert — Created the bug and described that LLB was informed by QuoVadis on March 8, 2019, stopped issuance, changed to 20-octet serials, and intended to revoke and reissue affected certificates.
- DigiCert — Confirmed that as of June 8 the last affected S/MIME certificates were revoked and remediation was complete.
- Community commenter — Asked not to close the bugs without CA Certificates Module input and deferred to Wayne to evaluate remediation.
- DigiCert — Acknowledged the clarification about closing the bug.
- Fastly representative — Commented that it appears remediation has been completed.