← Sectigo cases
Bugzilla #1724458 Ca Certificate Compliance

Sectigo Mojibake in certificate Subject fields and remediation rollout

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo opened this bug to disclose that its internal investigation found certificates containing Mojibake in Subject fields, including organizationName, organizationalUnitName, and localityName. The issue was first discovered on July 12, 2021 during an internal review of Sectigo’s certificate base, and Sectigo reported that 41 known certificates issued between March 31 and May 10, 2021 were affected. Sectigo said all known certificates were revoked by July 17, 2021, and then described a staged remediation plan that began with Character Set Review, followed by an exception list, a Unicode blocklist, and later automated pre-issuance checks based on FTFY. During the thread, Sectigo reported deploying these controls, including an updated treatment of OU fields, a Mojibake exception list, and automated checks for disallowed Unicode and Mojibake characters. Sectigo later said it had moved entirely to automated checking based on FTFY and would continue monitoring results. Mozilla indicated the case would be closed if there were no further remediation items or issues, and the bug is marked RESOLVED FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.98 41 comments
Chronology
  1. Sectigo’s internal investigation found certificates with Mojibake in Subject fields.
  2. Sectigo reported that all known affected certificates were revoked.
  3. Character Set Review went into production.
  4. Sectigo deployed its Mojibake exception list functionality.
  5. Sectigo deployed an automatic pre-issuance blocklist for selected Unicode characters.
  6. Sectigo deployed an automatic pre-issuance check for Mojibake characters based on FTFY.
  7. Sectigo said it had moved entirely to automated checking based on FTFY.
Thread Activity
  1. Sectigo — Sectigo opened the bug and attached a spreadsheet of affected certificates.
  2. Sectigo — Sectigo explained that its internal investigation found Mojibake in certificate Subject fields and that 41 known certificates were affected.
  3. Sectigo — Sectigo said it targeted September 18 for release of the Character Set Review functionality.
  4. Sectigo — Sectigo confirmed the Character Set Review process and said internal audit would review 100% of instances for the first six months.
  5. Sectigo — Sectigo outlined a three-stage response: detection/dispositioning, pre-issuance linting, and guided correction.
  6. Sectigo — Sectigo said Character Set Review was now in production and reviewed strings were being collected for analysis.
  7. Sectigo — Sectigo said it would stop checking OU fields for these characters and would ignore OU contents for Character Set Review.
  8. Sectigo — Sectigo said it had thousands of Character Set Review instances, built a Mojibake Exception List, and was targeting release that year.
  9. Mozilla representative — Mozilla said it would close the case on Friday, 14-Jan-2022 unless there were other remediation items or issues.
  10. Sectigo — Sectigo asked to keep the bug open because it was still researching a pre-issuance checker based on FTFY.
  11. Sectigo — Sectigo reported 21 certificates with U+FFFD, said 19 were revoked, and said it created a ticket to block issuance of that character.
  12. Sectigo — Sectigo said it had failed to report a previously revoked batch of 20 certificates with non-printable ASCII characters in Subject fields.
  13. Sectigo — Sectigo said it deployed an automatic pre-issuance blocklist for selected Unicode characters.
  14. Sectigo — Sectigo said it deployed an automatic pre-issuance check for Mojibake characters based on FTFY.
  15. Sectigo — Sectigo said it had completed its mitigation and that the automated systems would eventually replace Character Set Review.
  16. Sectigo — Sectigo said it had thoroughly investigated the matter, had an automated solution in place, and was ready to close the bug.
  17. Mozilla representative — Mozilla scheduled the bug for closure on 2022-03-18.
  18. Sectigo — Sectigo said it had moved entirely to automated checking based on FTFY and would monitor results for some time.
Participants
Sectigo Community commenter Mozilla representative
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1720744 RESOLVED Ca Certificate Compliance Opened 2021-07-15 · Closed 2023-02-22 · 100% similar
Sectigo: State name in localityName
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 97% similar
Sectigo: Subject field with unvalidated information included in certificates
#1793789 RESOLVED Ca Certificate Compliance Opened 2022-10-05 · Closed 2023-02-22 · 97% similar
Sectigo: Incorrect JOI
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 96% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action