← Eviden cases
Bugzilla #1540961 Self Reported Incident

Atos: Insufficient Serial Number Entropy

RESOLVED FIXED Eviden
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Atos CA discovered a compliance issue regarding insufficient entropy in the serial numbers of certificates issued from its Trusted Root CAs. The issue was identified during a self-assessment on March 18, 2019, which revealed that the serial number lengths were only 63 bits due to a misconfiguration. Atos took immediate action by stopping the issuance of non-compliant certificates and began replacing affected certificates. By May 31, 2019, Atos had revoked all affected certificates, except for some S/MIME certificates on smartcards, which they opted not to revoke due to customer impact. The CA has since implemented changes to ensure compliance with the Baseline Requirements.

Model: gpt-4o-mini Generated: 2026-06-13 18:10 UTC Revised: 2026-06-16 18:29 UTC Confidence: 0.85 16 comments
Chronology
  1. Atos CA conducted a self-assessment and identified insufficient serial number entropy.
  2. Atos CA completed the revocation of all affected certificates.
Thread Activity
  1. Disabled representative — Atos CA reported the issue and outlined the timeline of actions taken.
  2. Disabled representative — Atos CA provided an update on the ongoing certificate exchange process.
  3. Disabled representative — Atos CA confirmed that all affected certificates were revoked and compliance measures were implemented.
Participants
Disabled representative Mozilla representative Community commenter Atos Fastly representative
External References
Similar Local Cases
#1649963 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 95% similar
Atos: Incorrect OCSP Delegated Responder Certificate
#1534429 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2019-03-11 · Closed 2023-02-22 · 83% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1462844 RESOLVED Self Reported Incident Revocation Issue Opened 2018-05-19 · Closed 2023-02-22 · 82% similar
GoDaddy: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString
#1534429 RESOLVED Incident Self Reported Incident Opened 2019-03-11 · Closed 2023-02-22 · 80% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1509002 RESOLVED Self Reported Incident Opened 2018-11-21 · Closed 2023-02-22 · 78% similar
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
#1467414 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-06-07 · Closed 2023-02-22 · 78% similar
GDCA: Misissuance of certificates with small RSA keys
#1448986 RESOLVED Self Reported Incident Opened 2018-03-26 · Closed 2023-02-22 · 78% similar
Entrust: IP Address in dNSName form
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 78% similar
CFCA: Wrong SerialNumber encoding

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action