← Eviden cases
Bugzilla #1540961 Certificate Problem Report

Atos: Insufficient Serial Number Entropy

RESOLVED FIXED Eviden
AI Summary

Atos identified an issue with insufficient entropy in the serial numbers of certificates issued from their Trusted Root CAs. The problem was discovered during a self-compliance check prompted by discussions in the Mozilla security policy community. Affected certificates had serial numbers of only 63 bits due to a misconfiguration, leading to potential security vulnerabilities. Atos has since upgraded their systems and ceased issuing certificates with the problem, implementing a plan to revoke affected certificates by June 30, 2019. The incident has led to improvements in their compliance processes.

Model: gpt-4o-mini Generated: 2026-06-13 18:10 UTC Confidence: 0.95
Chronology
  1. Atos TC performed self-assessment on issued certificates.
  2. Atos TC informed certificate holders about renewal process.
  3. Revocation of all affected server certificates planned.
  4. All affected CA certificates and server certificates revoked.
Participants
u636358@disabled.tld jcristau@mozilla.com ryan.sleevi@gmail.com thomas.2.schwieters@atos.net wthayer@fastly.com
External References
Similar Local Cases
#1538638 RESOLVED Certificate Problem Report Opened 2019-03-25 · Closed 2023-02-22 · 61% similar
Firmaprofesional: AC Firmaprofesional - INFRAESTRUCTURA insufficient serial number entropy
#1536831 RESOLVED Certificate Problem Report Opened 2019-03-20 · Closed 2023-02-22 · 60% similar
GDCA: Insufficient Serial Number Entropy
#1534429 RESOLVED Certificate Problem Report Opened 2019-03-11 · Closed 2023-02-22 · 59% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1534429 RESOLVED Certificate Problem Report Opened 2019-03-11 · Closed 2023-02-22 · 59% similar
Camerfirma: Multicert SSL CA 001: Insufficient serial number entropy
#1579509 RESOLVED Certificate Problem Report Opened 2019-09-06 · Closed 2022-11-14 · 57% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1554259 RESOLVED Certificate Problem Report Opened 2019-05-24 · Closed 2023-02-22 · 56% similar
GlobalSign: SPKI lacks explicit NULL parameter,
#1579413 RESOLVED Certificate Problem Report Opened 2019-09-06 · Closed 2022-11-14 · 55% similar
GlobalSign: OCSP Responder Returns invalid values for Some Precertificates
#1575880 RESOLVED Certificate Problem Report Opened 2019-08-22 · Closed 2023-02-22 · 53% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action