← Sectigo cases
Bugzilla #1853987 Certificate Misissuance

Sectigo: S/MIME certificates with “(null)” string value in subject attributes

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that, during a manual review of its S/MIME certificate issuance, it noticed certificates issued with the literal string “(null)” in subject:givenName and/or subject:surname attributes. Sectigo stated that, due to certificate profile settings, these subject values could be included in subject:commonName as well. Sectigo traced the issue to an external Identity Provider (IdP) used by an Enterprise RA customer, where missing attribute values were represented as the literal string “(null)”, leading Sectigo systems to issue certificates with bogus subject data. Sectigo developed and deployed a patch to block issuance of any S/MIME certificate where subject:givenName and/or subject:surname are requested to be “(null)”. Sectigo scheduled customer notifications and revocation events, revoking the initially discovered 8 certificates on September 18, 2023 and then identifying a total of 126 affected certificates, with remaining certificates revoked by September 22, 2023. Mozilla staff commented that the bug should be closed as RESOLVED FIXED, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.90 5 comments
Chronology
  1. Sectigo initiated internal review after noticing S/MIME certificates containing “(null)” in subject attributes.
  2. Sectigo deployed a patch to block issuance of S/MIME certificates requesting “(null)” subject:givenName and/or subject:surname.
  3. Sectigo revoked the initially discovered certificates and identified additional affected certificates.
  4. Sectigo completed revocation of the remaining affected certificates.
Thread Activity
  1. Sectigo — Created the bug describing that manual review found S/MIME certificates with “(null)” in subject:givenName and/or subject:surname, traced it to an IdP connector, deployed a blocking patch, and scheduled customer notifications and revocations.
  2. Sectigo — Reported that all remaining certificates were revoked by September 22, 2023 and that remediation concluded the investigation.
  3. Sectigo — Asked the community and Mozilla for opinions on whether the bug should be RESOLVED FIXED or RESOLVED INVALID.
  4. Mozilla representative — Said the bug should be closed as RESOLVED FIXED rather than RESOLVED INVALID, noting CA responsibility for well-formed certificates.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1860299 RESOLVED Certificate Misissuance Opened 2023-10-20 · Closed 2023-12-02 · 99% similar
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 97% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1756847 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 96% similar
Sectigo: SC45 DCV Reuse Error
#1829746 RESOLVED Certificate Misissuance Opened 2023-04-24 · Closed 2023-06-02 · 96% similar
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
#1897538 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2026-06-10 · 96% similar
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 91% similar
Sectigo: Subject field with unvalidated information included in certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 88% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1708934 RESOLVED Certificate Misissuance Opened 2021-05-01 · Closed 2023-02-22 · 88% similar
Sectigo: Invalid postalCode field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action