A recently discovered flaw in common practices reveals that potentially millions of active SSL certificates fall short of cryptographic requirements. Learn how it is that 64-bit certificate serial numbers might offer only 63 bits of entropy and what CAs have to do about it.