← DigiCert cases
Bugzilla #1540315 Certificate Misissuance

QuoVadis: LLB insufficient Serial Number Entropy

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns QuoVadis-related S/MIME certificates issued by LLB (an external subCA signed by QuoVadis) that had insufficient serial number entropy. LLB was informed by QuoVadis on March 8, 2019 about possible issues with 64-bit entropy in certificate serial numbers. In response, LLB stopped issuing certificates and changed its configuration to use 20-octet serials, after analyzing affected certificates with an external consultant. LLB stated that certificates were only issued to internal employees and that it intended to revoke and reissue the affected certificates. LLB later confirmed that, as of June 8, the last of the affected S/MIME certificates had been revoked and that remediation was complete. The bug was marked RESOLVED with resolution FIXED, and other participants noted that remediation appeared completed but asked that the bug not be closed without CA Certificates Module input.

Model: gpt-5.4-nano Generated: 2026-06-13 18:10 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.50 5 comments
Chronology
  1. LLB was informed by QuoVadis about possible issues with 64-bit entropy in certificate serial numbers.
  2. LLB received a report from an external consultant about affected CA and certificates.
  3. LLB reported back to QuoVadis and continued discussion.
  4. LLB revoked the last of the affected S/MIME certificates and considered remediation complete.
Thread Activity
  1. DigiCert — Created the bug and described that LLB was informed by QuoVadis on March 8, 2019, stopped issuance, changed to 20-octet serials, and intended to revoke and reissue affected certificates.
  2. DigiCert — Confirmed that as of June 8 the last affected S/MIME certificates were revoked and remediation was complete.
  3. Community commenter — Asked not to close the bugs without CA Certificates Module input and deferred to Wayne to evaluate remediation.
  4. DigiCert — Acknowledged the clarification about closing the bug.
  5. Fastly representative — Commented that it appears remediation has been completed.
Participants
DigiCert Community commenter Fastly representative
External References
Similar Local Cases
#1589047 RESOLVED Certificate Misissuance Opened 2019-10-16 · Closed 2023-02-22 · 69% similar
QuoVadis: Incorrect EV jurisdiction of incorporation information
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 64% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 61% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 49% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1576283 RESOLVED Certificate Misissuance Opened 2019-08-23 · Closed 2023-02-22 · 48% similar
QuoVadis: N/A in EV serialNumber field
#1581234 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-13 · Closed 2023-02-22 · 47% similar
QuoVadis: EV JOI Issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action