← Sectigo cases
Bugzilla #1853987 Certificate Problem Report

Sectigo: S/MIME certificates with (null) string value in subject attributes

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified an issue where S/MIME certificates were issued with '(null)' in the subject:givenName and subject:surname attributes. This was discovered during a manual review, leading to an internal investigation that revealed a bug in their system caused by an external Identity Provider (IdP). A total of 126 certificates were affected, and Sectigo has since deployed a patch to prevent further issuance of such certificates. All affected certificates were revoked by September 22, 2023, concluding their remediation efforts.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 1.00
Chronology
  1. Internal ticket created to review issued S/MIME certificates.
  2. Patch deployed to block issuance of certificates with '(null)' string.
  3. Initial 8 certificates revoked.
  4. All remaining certificates revoked.
Participants
Martijn Katerbarg Ben Wilson
External References
Similar Local Cases
#1793787 RESOLVED Certificate Problem Report Opened 2022-10-05 · Closed 2023-02-22 · 68% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 68% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1912225 RESOLVED Certificate Problem Report Opened 2024-08-08 · Closed 2024-09-26 · 68% similar
Sectigo: HTML encoded characters in subject attribute values
#1910451 RESOLVED Certificate Problem Report Opened 2024-07-29 · Closed 2024-08-21 · 66% similar
Sectigo: Missing character in subject:organizationName attribute value
#1818073 RESOLVED Certificate Problem Report Opened 2023-02-21 · Closed 2023-06-28 · 65% similar
Sectigo: Late revocation for incomplete Subject organizationName
#1891039 RESOLVED Certificate Problem Report Opened 2024-04-11 · Closed 2024-05-05 · 65% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1908690 RESOLVED Certificate Problem Report Opened 2024-07-18 · Closed 2024-08-23 · 65% similar
Sectigo: Temporary unavailability for subset of CRLs
#1800756 RESOLVED Certificate Problem Report Opened 2022-11-15 · Closed 2023-02-22 · 64% similar
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action