Atos: Insufficient Serial Number Entropy
Atos CA discovered a compliance issue regarding insufficient entropy in the serial numbers of certificates issued from its Trusted Root CAs. The issue was identified during a self-assessment on March 18, 2019, which revealed that the serial number lengths were only 63 bits due to a misconfiguration. Atos took immediate action by stopping the issuance of non-compliant certificates and began replacing affected certificates. By May 31, 2019, Atos had revoked all affected certificates, except for some S/MIME certificates on smartcards, which they opted not to revoke due to customer impact. The CA has since implemented changes to ensure compliance with the Baseline Requirements.
- Atos CA conducted a self-assessment and identified insufficient serial number entropy.
- Atos CA completed the revocation of all affected certificates.
- Disabled representative — Atos CA reported the issue and outlined the timeline of actions taken.
- Disabled representative — Atos CA provided an update on the ongoing certificate exchange process.
- Disabled representative — Atos CA confirmed that all affected certificates were revoked and compliance measures were implemented.