Sectigo: S/MIME certificates with “(null)” string value in subject attributes
Sectigo reported that, during a manual review of its S/MIME certificate issuance, it noticed certificates issued with the literal string “(null)” in subject:givenName and/or subject:surname attributes. Sectigo stated that, due to certificate profile settings, these subject values could be included in subject:commonName as well. Sectigo traced the issue to an external Identity Provider (IdP) used by an Enterprise RA customer, where missing attribute values were represented as the literal string “(null)”, leading Sectigo systems to issue certificates with bogus subject data. Sectigo developed and deployed a patch to block issuance of any S/MIME certificate where subject:givenName and/or subject:surname are requested to be “(null)”. Sectigo scheduled customer notifications and revocation events, revoking the initially discovered 8 certificates on September 18, 2023 and then identifying a total of 126 affected certificates, with remaining certificates revoked by September 22, 2023. Mozilla staff commented that the bug should be closed as RESOLVED FIXED, and the bug is marked RESOLVED with resolution FIXED.
- Sectigo initiated internal review after noticing S/MIME certificates containing “(null)” in subject attributes.
- Sectigo deployed a patch to block issuance of S/MIME certificates requesting “(null)” subject:givenName and/or subject:surname.
- Sectigo revoked the initially discovered certificates and identified additional affected certificates.
- Sectigo completed revocation of the remaining affected certificates.
- Sectigo — Created the bug describing that manual review found S/MIME certificates with “(null)” in subject:givenName and/or subject:surname, traced it to an IdP connector, deployed a blocking patch, and scheduled customer notifications and revocations.
- Sectigo — Reported that all remaining certificates were revoked by September 22, 2023 and that remediation concluded the investigation.
- Sectigo — Asked the community and Mozilla for opinions on whether the bug should be RESOLVED FIXED or RESOLVED INVALID.
- Mozilla representative — Said the bug should be closed as RESOLVED FIXED rather than RESOLVED INVALID, noting CA responsibility for well-formed certificates.