← Atos cases
Bugzilla #1540961 Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Remediation Tracking

Atos self-reported insufficient serial number entropy in issued certificates

RESOLVED FIXED Atos
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Atos opened this case after its own self-compliance check found that certificates issued from Atos Trusted Root CAs had insufficient serial number entropy. The report says the issue affected server certificates from Atos TrustedRoot Server-CA 2017 and Atos TrustedRoot Server-CA 2013, and Atos later stated that S/MIME certificates were also affected. Atos said it stopped issuing certificates with the problem, upgraded its CA software, changed the serial number octet size to 96 bits, and began replacement planning. The thread then focused on revocation and replacement timing, including requests for deadline extensions and Mozilla feedback that the CA needed to meet its prior commitments. Atos later reported that all affected CA certificates, server certificates, and software-issued S/MIME certificates were revoked, with smartcard S/MIME certificates excluded from revocation. The bug was resolved as FIXED, and a final comment stated that remediation appeared completed.

Model: gpt-5.4-mini Generated: 2026-09-06 11:09 UTC Confidence: 0.98 16 comments
Chronology
  1. Atos identified insufficient serial number entropy in certificates issued from its Trusted Root CAs during a self-assessment.
  2. Atos changed the CA serial number octet size to 12 for certificates issued by Atos TrustedRoot Server-CA 2019 and started replacement planning.
  3. Atos reported that the old Atos TrustedRoot Server CA 2017 was no longer issuing certificates and that remaining affected certificates were to be revoked.
  4. Atos reported that all affected CA certificates, server certificates, and software-issued S/MIME certificates were revoked, with smartcard S/MIME certificates not revoked.
Thread Activity
  1. Disabled representative — Atos reported the self-assessment finding, described the affected certificates, said issuance with wrong entropy had stopped, and listed renewal and revocation steps.
  2. Mozilla representative — Mozilla asked why there were delays between the mdsp discussion, the self-assessment, the report, continued issuance, and revocation.
  3. Disabled representative — Atos said it had stopped issuing user certificates after clarification, noted about 200,000 S/MIME certificates needed revocation and replacement, and said it would keep the incident report a priority.
  4. Disabled representative — Atos said customer replacement was ongoing, old certificates would be revoked after replacement, and affected sub-CAs would be revoked and replaced by 2019-05-31.
  5. Disabled representative — Atos asked to extend the revocation deadline for remaining certificates to 2019-06-30.
  6. Disabled representative — Atos said the old server CA was no longer issuing, gave revocation counts, and proposed a manual revocation schedule through 2019-06-30.
  7. Community commenter — Mozilla said extensions were not acceptable and that the CA needed to follow its commitments.
  8. Disabled representative — Atos said it informed customers and revoked all remaining affected certificates.
  9. Disabled representative — Atos reported that all affected CA, server, and software-issued S/MIME certificates were revoked, the serial number size was changed, and a validator script was added.
  10. Fastly representative — A commenter said remediation of the incident appeared completed.
Participants
Disabled representative Mozilla representative Community commenter Atos Fastly representative
Similar Local Cases
#1649963 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 97% similar
Atos: Incorrect OCSP Delegated Responder Certificate
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 92% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 90% similar
Izenpe: Multiple invalid EV certificates issued
#1538638 RESOLVED Ca Certificate Compliance Self Reported Incident Revocation Issue Opened 2019-03-25 · Closed 2023-02-22 · 90% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 88% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 88% similar
Camerfirma: Govern d'Andorra audits
#1525710 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-02-06 · Closed 2023-02-22 · 87% similar
Amazon Trust Services: Test revoked certificates with invalid validity period
#1569266 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-26 · Closed 2023-02-22 · 87% similar
Amazon Trust Services: No Space In Private Organization

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action