← Actalis cases
Bugzilla #1534295 Certificate Misissuance

Actalis: Insufficient serial number entropy

RESOLVED FIXED Actalis
AI Summary

Actalis identified an issue with insufficient entropy in the serial numbers of approximately 350,000 certificates issued between September 30, 2016, and March 6, 2019. The problem stemmed from the EJBCA software's unexpected behavior. Following the discovery on March 3, 2019, Actalis implemented a fix on March 6, ensuring all subsequent certificates had adequate entropy. The revocation of affected certificates began shortly after, with significant progress reported, although challenges arose due to the complexity of customer organizations and their internal processes. By August 1, 2019, Actalis confirmed that all impacted certificates had been revoked or expired.

Model: gpt-4o-mini Generated: 2026-06-13 18:07 UTC Confidence: 0.95
Chronology
  1. Actalis became aware of insufficient entropy in certificate serial numbers.
  2. Fix implemented to ensure certificates have adequate entropy.
  3. All impacted certificates confirmed revoked or expired.
Participants
Adriano Santoni Ryan Sleevi Giorgio Girelli
External References
Similar Local Cases
#1405817 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 58% similar
Actalis: Certs issued with same issuer and serial number
#1536213 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 51% similar
ACCV: Insufficient serial number entropy
#1397954 RESOLVED Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 50% similar
DigiCert / Siemens: Insufficient Serial Number Entropy
#1569266 RESOLVED Certificate Misissuance Opened 2019-07-26 · Closed 2023-02-22 · 50% similar
Amazon Trust Services: No Space In Private Organization
#1595921 RESOLVED Certificate Misissuance Opened 2019-11-12 · Closed 2023-02-22 · 49% similar
DigiCert: Domain validation skipped
#1894560 RESOLVED Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 49% similar
DigiCert: Incorrect case in Business Category
#1391056 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 48% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1520876 RESOLVED Certificate Misissuance Opened 2019-01-17 · Closed 2023-02-22 · 47% similar
Entrust: Late mis-issue certificate revocation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action