Asseco Data Systems / Certum: Subordinate certificates with sequential serial number
Asseco Data Systems S.A. / Certum reported a compliance issue discovered during its periodic self-audit: it found that the serial numbers of subordinate certificates were sequential, which it suspected was generated with insufficient entropy. The CA confirmed that two subordinate certificates had sequential serial numbers and disclosed the findings in this bug, then performed a detailed investigation to identify the root cause. The CA revoked the first subordinate certificate identified in the initial finding and later identified and confirmed the reason for the sequential serial numbers. It implemented a fix for the software used to generate subordinate certificates, expanded tests for CA certificates, and revoked the second subordinate certificate from the initial finding. During a comprehensive scan, the CA found a third subordinate certificate with a sequential serial number and scheduled its revocation; it later stated that the third certificate was revoked as scheduled. The CA also updated its systems to prevent additional issuance of CA certificates with a sequential serial number, and the bug was resolved as FIXED.
- During a periodic self-audit, the CA detected subordinate certificates with sequential serial numbers and suspected insufficient entropy in serial generation.
- The CA began a detailed investigation and revoked the first identified subordinate certificate.
- The CA implemented a fix for subordinate certificate serial generation software and expanded tests for CA certificates.
- The CA revoked the second identified subordinate certificate and completed a review that found no other affected CA certificates; it also identified a third affected subordinate certificate.
- The CA revoked the third subordinate certificate as scheduled.
- The bug was resolved as FIXED.
- Asseco Data Systems S.A. — Reported that the CA’s periodic self-audit detected sequential serial numbers in subordinate certificates and said it would provide a full incident report within 7 days.
- Asseco Data Systems S.A. — Provided a detailed timeline and stated that two subordinate certificates were confirmed to have sequential serial numbers, with subsequent investigation and revocations planned.
- Asseco Data Systems S.A. — Confirmed that the specified certificate on crt.sh was revoked as scheduled.
- Thisisntrocket representative — Noted that one certificate showed "good" on OCSP while the other linked certificates showed "Revoked (superseded)".
- Asseco Data Systems S.A. — Said the CA verified OCSP status after updating its database and that crt.sh OCSP validator appeared to have delayed status updates, now showing revoked.
- Asseco Data Systems S.A. — Stated there were no further updates.
- Mozilla representative — Indicated Mozilla intended to close the bug on or about 2-June-2023 unless there were concerns.