QuoVadis: hostnames not in preferred name syntax (trailing/leading hyphens in domain labels)
The QuoVadis-operated CA for HydrantID disclosed that it issued a certificate containing a hostname syntax issue: a trailing hyphen in a domain label within the SAN extension. HydrantID and QuoVadis identified the certificate after issuance using crt.sh linting, and then confirmed the issue was limited to a single current certificate. The CA reported that the certificate was revoked on Oct 26, and that it investigated the root cause on Oct 27 and confirmed no other affected certificates existed. QuoVadis stated that its issuance systems’ filters and linting (including ZLint) did not catch this specific problem, and that the issue was found post-issuance using certlint. The CA created a patch for its QuoVadis legacy systems to ensure trailing and leading hyphens are caught at all levels of domains, and said it would be implemented to production systems before Nov 15. QuoVadis also stated that DigiCert CertCentral already catches the issue and that no such certificates exist under the DigiCert roots, while noting an enhancement to implement a secondary catch at the CA level. The CA confirmed the updates were completed and requested closure; the bug was resolved as FIXED.
- A certificate was issued containing a trailing hyphen in a domain label within the SAN extension.
- The problematic certificate was revoked.
- A patch to catch leading/trailing hyphens in domain labels was implemented to production systems.
- DigiCert — Described how the CA became aware of the issue, provided a timeline, stated the certificate was revoked, and outlined remediation including a patch for legacy systems and a planned secondary linting enhancement.
- DigiCert — Attached fingerprints for revoked certificates with hostnames not in preferred name syntax.
- DigiCert — Reported that a zlint PR was opened to add a lint checking Domain Labels are LDH-Labels, intended to detect this issue.
- DigiCert — Confirmed the patch would be deployed by end of day on Nov 15 and that the CA would request closure afterward.
- DigiCert — Confirmed the updates were completed and requested the disclosure be marked closed.
- Mozilla representative — Indicated Mozilla would close the bug on Nov 19 unless additional questions remained.