← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1573490
Certificate Problem Report
PKIoverheid: CIBG insufficient serial number entropy
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The PKIoverheid CA identified an issue with insufficient entropy in the serial numbers of TLS certificates issued by CIBG. The problem was first noted on March 8, 2019, leading to an investigation that revealed approximately 4,129 certificates were affected. CIBG transitioned to a private CA for TLS certificate issuance in December 2017, and all affected certificates were successfully revoked by October 2020. The issue stemmed from a misinterpretation of compliance requirements, which was acknowledged in the discussions.
Chronology
- Investigation initiated after discussions in mozilla.dev.security.policy.
- CIBG confirmed the issue affected their certificates.
- CIBG completed revocation of affected certificates.
Participants
Jorik van 't Hof
Wayne Thayer
Ryan Sleevi
Jochem van den Berge
External References
Similar Local Cases
PKIoverheid: KPN Insufficient Serial Number Entropy
PKIoverheid: Incorrect OCSP Delegated Responder Certificate
PKIoverheid: TSP CPS lacks problem reporting instructions
TrustCor: Insufficient Serial Number Entropy
GoDaddy: Insufficient serial number entropy
QuoVadis: LLB insufficient Serial Number Entropy
Entrust: IP Address in dNSName form
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280