Atos self-reported insufficient serial number entropy in issued certificates
Atos opened this case after its own self-compliance check found that certificates issued from Atos Trusted Root CAs had insufficient serial number entropy. The report says the issue affected server certificates from Atos TrustedRoot Server-CA 2017 and Atos TrustedRoot Server-CA 2013, and Atos later stated that S/MIME certificates were also affected. Atos said it stopped issuing certificates with the problem, upgraded its CA software, changed the serial number octet size to 96 bits, and began replacement planning. The thread then focused on revocation and replacement timing, including requests for deadline extensions and Mozilla feedback that the CA needed to meet its prior commitments. Atos later reported that all affected CA certificates, server certificates, and software-issued S/MIME certificates were revoked, with smartcard S/MIME certificates excluded from revocation. The bug was resolved as FIXED, and a final comment stated that remediation appeared completed.
- Atos identified insufficient serial number entropy in certificates issued from its Trusted Root CAs during a self-assessment.
- Atos changed the CA serial number octet size to 12 for certificates issued by Atos TrustedRoot Server-CA 2019 and started replacement planning.
- Atos reported that the old Atos TrustedRoot Server CA 2017 was no longer issuing certificates and that remaining affected certificates were to be revoked.
- Atos reported that all affected CA certificates, server certificates, and software-issued S/MIME certificates were revoked, with smartcard S/MIME certificates not revoked.
- Disabled representative — Atos reported the self-assessment finding, described the affected certificates, said issuance with wrong entropy had stopped, and listed renewal and revocation steps.
- Mozilla representative — Mozilla asked why there were delays between the mdsp discussion, the self-assessment, the report, continued issuance, and revocation.
- Disabled representative — Atos said it had stopped issuing user certificates after clarification, noted about 200,000 S/MIME certificates needed revocation and replacement, and said it would keep the incident report a priority.
- Disabled representative — Atos said customer replacement was ongoing, old certificates would be revoked after replacement, and affected sub-CAs would be revoked and replaced by 2019-05-31.
- Disabled representative — Atos asked to extend the revocation deadline for remaining certificates to 2019-06-30.
- Disabled representative — Atos said the old server CA was no longer issuing, gave revocation counts, and proposed a manual revocation schedule through 2019-06-30.
- Community commenter — Mozilla said extensions were not acceptable and that the CA needed to follow its commitments.
- Disabled representative — Atos said it informed customers and revoked all remaining affected certificates.
- Disabled representative — Atos reported that all affected CA, server, and software-issued S/MIME certificates were revoked, the serial number size was changed, and a validator script was added.
- Fastly representative — A commenter said remediation of the incident appeared completed.