← e-tugra cases
Bugzilla #1542302 Self Reported Incident

E-Tugra: Insufficient serial number entropy

RESOLVED FIXED e-tugra
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosure by E-Tugra about an issue involving insufficient serial number entropy in certificates. E-Tugra said it became aware of the problem through EJBCA 63-bit entropy problem reporting and internal monitoring after searching its certificates. E-Tugra investigated and increased the size of serial number fields, updating EJBCA settings to set the serial number length parameter to 16 bytes (128 bits) from 8 bytes. E-Tugra also reissued certificates that were not revoked or expired, then revoked existing certificates, stating that as of March 13 the reasons for the problem were fixed and no more certificates would be produced with these problems. In the thread, Mozilla participants asked why reporting was deferred for over one month; E-Tugra responded that it waited to complete revocation and re-control of its systems before posting the incident report. E-Tugra stated it would develop and update internal incident reporting procedures and risk analysis/audits to ensure more proactive notification, and later indicated that remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 18:10 UTC Revised: 2026-06-16 18:31 UTC Confidence: 0.90 10 comments
Chronology
  1. E-Tugra issued certificates later identified as affected by the serial number entropy problem (min issue date stated).
  2. E-Tugra received an announcement from its CA software vendor (EJBCA) about the entropy problem.
  3. E-Tugra investigated its systems and began fixes, including increasing serial number field sizes.
  4. E-Tugra updated systems and set EJBCA serial number length to 16 bytes (128 bits) from 8 bytes, and began reissuing certificates.
  5. E-Tugra completed updates and started reissuing certificates and revoking existing certificates.
  6. E-Tugra posted the incident report in this bug after completing revocation and re-control.
  7. E-Tugra reported completion of enhanced internal incident reporting procedures and risk/audit review.
Thread Activity
  1. E-Tugra — Opened the incident report describing insufficient serial number entropy, the timeline of investigation/fixes, reissuance and revocation, and provided a spreadsheet link for affected certificates.
  2. Fastly representative — Asked why it took E-Tugra over one month to report the incident.
  3. E-Tugra — Explained the delay by stating E-Tugra waited to complete revocation and re-control of its systems before posting the incident report.
  4. Community commenter — Asked for more detail on deferring reporting until revocation was complete and whether steps would be taken for more proactive notification.
  5. E-Tugra — Acknowledged the reporting gap and stated it would develop internal incident reporting procedures and improve risk analysis/audits to avoid delays and misunderstandings.
  6. Fastly representative — Requested an update to the bug once the actions described in comment #4 were completed.
  7. Mozilla representative — Noted the priority flag was not set and asked for review.
  8. Mozilla representative — Changed the bug type to Task so it would not be part of Mozilla's regular bug triage process.
  9. E-Tugra — Reported that enhanced internal incident reporting procedures and risk/audit review were completed to enable more proactive notification.
  10. Fastly representative — Indicated it appears remediation is complete.
Participants
E-Tugra Fastly representative Community commenter Mozilla representative
Similar Local Cases
#1801345 RESOLVED Self Reported Incident Security Incident Opened 2022-11-18 · Closed 2023-07-21 · 88% similar
E-Tugra: Incident Report (Security Issues)
#1687139 RESOLVED Self Reported Incident Opened 2021-01-16 · Closed 2023-02-22 · 84% similar
E-Tugra: commonName not in SAN
#1575530 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-08-21 · Closed 2023-02-22 · 84% similar
Camerfirma: Govern d'Andorra audits
#1582601 RESOLVED Self Reported Incident Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 83% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1599503 RESOLVED Self Reported Incident Opened 2019-11-26 · Closed 2024-06-30 · 82% similar
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports
#1391064 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-08-16 · Closed 2023-02-22 · 82% similar
SECOM: Non-BR-Compliant Certificate Issuance
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 82% similar
CFCA: Wrong SerialNumber encoding
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 81% similar
NetLock: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action