← TrustCor Systems cases
Bugzilla #1532399
Certificate Problem Report
TrustCor: Insufficient Serial Number Entropy
RESOLVED
FIXED
TrustCor Systems
AI Summary
TrustCor Systems identified an issue with insufficient entropy in the serial number generation for certificates, which could lead to non-compliance with Baseline Requirements. Following the discovery, TrustCor suspended SSL certificate issuance and conducted a thorough investigation. They found five mis-issued certificates, all of which were promptly revoked. TrustCor has since implemented a revised compliance process to ensure adherence to serial number requirements, including monitoring and testing to prevent future misissuance.
Chronology
- TrustCor first becomes aware of the potential issue.
- TrustCor identifies five mis-issued certificates and revokes them.
- Certificate issuance resumed with improved entropy.
Participants
Wayne Thayer
Neil Dunbar
Ryan Sleevi
External References
Similar Local Cases
PKIoverheid: CIBG insufficient serial number entropy
GoDaddy: Insufficient serial number entropy
Sectigo: "Some-State" in stateOrProvinceName
PKIoverheid: KPN Insufficient Serial Number Entropy
DigiCert: CAA Checking Issue
Entrust: IP Address in dNSName form
CFCA: Internal iPAddress in certificate
CFCA: invalid dnsNames