Sectigo Mojibake in certificate Subject fields and remediation rollout
Sectigo opened this bug to disclose that its internal investigation found certificates containing Mojibake in Subject fields, including organizationName, organizationalUnitName, and localityName. The issue was first discovered on July 12, 2021 during an internal review of Sectigo’s certificate base, and Sectigo reported that 41 known certificates issued between March 31 and May 10, 2021 were affected. Sectigo said all known certificates were revoked by July 17, 2021, and then described a staged remediation plan that began with Character Set Review, followed by an exception list, a Unicode blocklist, and later automated pre-issuance checks based on FTFY. During the thread, Sectigo reported deploying these controls, including an updated treatment of OU fields, a Mojibake exception list, and automated checks for disallowed Unicode and Mojibake characters. Sectigo later said it had moved entirely to automated checking based on FTFY and would continue monitoring results. Mozilla indicated the case would be closed if there were no further remediation items or issues, and the bug is marked RESOLVED FIXED.
- Sectigo’s internal investigation found certificates with Mojibake in Subject fields.
- Sectigo reported that all known affected certificates were revoked.
- Character Set Review went into production.
- Sectigo deployed its Mojibake exception list functionality.
- Sectigo deployed an automatic pre-issuance blocklist for selected Unicode characters.
- Sectigo deployed an automatic pre-issuance check for Mojibake characters based on FTFY.
- Sectigo said it had moved entirely to automated checking based on FTFY.
- Sectigo — Sectigo opened the bug and attached a spreadsheet of affected certificates.
- Sectigo — Sectigo explained that its internal investigation found Mojibake in certificate Subject fields and that 41 known certificates were affected.
- Sectigo — Sectigo said it targeted September 18 for release of the Character Set Review functionality.
- Sectigo — Sectigo confirmed the Character Set Review process and said internal audit would review 100% of instances for the first six months.
- Sectigo — Sectigo outlined a three-stage response: detection/dispositioning, pre-issuance linting, and guided correction.
- Sectigo — Sectigo said Character Set Review was now in production and reviewed strings were being collected for analysis.
- Sectigo — Sectigo said it would stop checking OU fields for these characters and would ignore OU contents for Character Set Review.
- Sectigo — Sectigo said it had thousands of Character Set Review instances, built a Mojibake Exception List, and was targeting release that year.
- Mozilla representative — Mozilla said it would close the case on Friday, 14-Jan-2022 unless there were other remediation items or issues.
- Sectigo — Sectigo asked to keep the bug open because it was still researching a pre-issuance checker based on FTFY.
- Sectigo — Sectigo reported 21 certificates with U+FFFD, said 19 were revoked, and said it created a ticket to block issuance of that character.
- Sectigo — Sectigo said it had failed to report a previously revoked batch of 20 certificates with non-printable ASCII characters in Subject fields.
- Sectigo — Sectigo said it deployed an automatic pre-issuance blocklist for selected Unicode characters.
- Sectigo — Sectigo said it deployed an automatic pre-issuance check for Mojibake characters based on FTFY.
- Sectigo — Sectigo said it had completed its mitigation and that the automated systems would eventually replace Character Set Review.
- Sectigo — Sectigo said it had thoroughly investigated the matter, had an automated solution in place, and was ready to close the bug.
- Mozilla representative — Mozilla scheduled the bug for closure on 2022-03-18.
- Sectigo — Sectigo said it had moved entirely to automated checking based on FTFY and would monitor results for some time.