← e-tugra cases
Bugzilla #1542302
Certificate Problem Report
E-Tugra: Insufficient serial number entropy
RESOLVED
FIXED
e-tugra
AI Summary
E-Tugra identified an issue with insufficient entropy in the serial numbers of their certificates, which was reported through both community feedback and internal monitoring. The CA took immediate action, increasing the serial number length from 8 bytes to 16 bytes and revoking all affected certificates. The issue was resolved by March 13, 2019, and E-Tugra has since updated their internal incident reporting procedures to ensure timely notifications in the future. The incident report was submitted on April 5, 2019, after the revocation process was completed.
Chronology
- Announcement from EJBCA regarding the entropy issue.
- Investigation of the system began.
- Serial number length increased to 16 bytes.
- Reissue of all affected certificates started.
- Incident report submitted.
Participants
Davut Tokgöz
W. Thayer
Ryan Sleevi
External References
Similar Local Cases
E-Tugra: Intermittent OCSP response with status 'Unknown'
SECOM: Insufficient Serial Number Entropy
E-Tugra: Validity period > 825 days
E-Tugra: commonName not in SAN
Buypass: intermediate certificates not revoked within BR time period
GlobalSign: IP in dnsName
E-Tugra: The failure to revoke a certificate
E-Tugra: Delayed Response of Revocation Request