← Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV) cases
Bugzilla #1536213
Certificate Misissuance
ACCV: Insufficient serial number entropy
RESOLVED
FIXED
Government of Spain, Autoritat de Certificació de la Comunitat Valenciana (ACCV)
AI Summary
The Government of Spain's CA, ACCV, identified an issue with insufficient entropy in the serial numbers of approximately 1,800 certificates. The problem was detected on March 12, 2019, leading to a series of corrective actions including a patch to generate 128-bit serial numbers. Despite initial delays in revocation and replacement, ACCV successfully replaced all affected certificates by July 22, 2019. The CA has committed to improving its processes to prevent similar issues in the future.
Chronology
- ACCV began researching the serial number issue.
- ACCV deployed a fix to generate 128-bit serial numbers.
- All remaining affected certificates were replaced.
Participants
Jose Amador
Ryan Sleevi
External References
Similar Local Cases
DigiCert: Domain validation skipped
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
Actalis: Insufficient serial number entropy
Camerfirma: MULTICERT organizationName Too Long
GRCA: Misissued certificates: Invalid commonName, commonName not in SAN
Entrust: Issued Certificates to incorrect Organization
DigiCert / Siemens: Insufficient Serial Number Entropy
Amazon Trust Services: Misissuance of Subordinate Per CPS