← GoDaddy cases
Bugzilla #1533774
Certificate Problem Report
GoDaddy: Insufficient serial number entropy
RESOLVED
FIXED
GoDaddy
AI Summary
GoDaddy identified a significant issue with the entropy of certificate serial numbers, affecting over 12,000 live certificates. The problem was first noted on March 6, 2019, following discussions in the Mozilla security policy group. GoDaddy promptly addressed the issue by deploying a fix on March 7, 2019, and ceased issuing certificates with the defect. The CA has since revised its processes to ensure compliance with industry standards, including plans to upgrade serial number lengths to a minimum of 128 bits.
Chronology
- GoDaddy begins investigating the serial number issue.
- Fix deployed to production.
- GoDaddy identifies 12,152 live certificates affected.
- GoDaddy updates on the status of impacted certificates.
Participants
Wayne Thayer
Joanna Fox
Daymion Reynolds
Ryan Sleevi
External References
Similar Local Cases
GoDaddy: failure to revoke underscores
GoDaddy: Issues with State and Country fields
PKIoverheid: KPN Insufficient Serial Number Entropy
PKIoverheid: CIBG insufficient serial number entropy
TrustCor: Insufficient Serial Number Entropy
QuoVadis: LLB insufficient Serial Number Entropy
Consorci AOC: Non-BR-Compliant Certificate Issuance
DigiCert: CAA Checking Issue