← Sectigo cases
Bugzilla #1912225 Revocation Issue

Sectigo: HTML encoded characters in subject attribute values

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo received a Certificate Problem Report (CPR) on 2024-08-06 about a single certificate whose subject:organizationName attribute contained an HTML encoded “&” entity. In its investigation, Sectigo determined the certificate was misissued because the subject contained the HTML entity string “\&” instead of the “&” character. Sectigo reported that 11 certificates were affected, covering issuance dates from 2023-07-13 to 2024-03-05. Sectigo scheduled revocation for the initially reported certificate on 2024-08-11 and also created a revocation event for 10 additional misissued certificates on 2024-08-11. Sectigo implemented an update to its pkimetal ftfy integration (pushed to pkimetal) and later completed analysis of its pre-issuance ftfy integration, concluding the root cause differed from the issue already fixed in pkimetal. The bug was resolved as FIXED, and Sectigo requested closure after completing remaining action items, with Mozilla scheduling closure for 2024-09-20.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:03 UTC Confidence: 0.86 7 comments
Chronology
  1. Sectigo received a CPR reporting a certificate whose subject:organizationName contained an HTML-encoded “&” entity string.
  2. Sectigo revoked the initially reported certificate and 10 additional discovered misissued certificates.
  3. Sectigo completed remaining action items after a planned deployment.
Thread Activity
  1. Sectigo — Sectigo posted a preliminary incident report stating it was investigating the CPR and that the reported certificate was scheduled for revocation on 2024-08-11.
  2. Sectigo — Sectigo posted the incident report confirming the certificate was misissued, identifying 11 affected certificates, describing its investigation and revocation scheduling, and noting an update implemented for the pkimetal ftfy integration.
  3. Sectigo — Sectigo corrected an editorial mistake in the affected-certificate details and provided the corrected crt.sh links.
  4. Sectigo — Sectigo requested a next update for 2024-09-15 based on due dates in its action items.
  5. Sectigo — Sectigo announced it was still on track to complete action items through a scheduled deployment that weekend.
  6. Sectigo — Sectigo stated the planned deployment was completed successfully, all remaining action items were completed, and it requested closing the bug.
  7. Mozilla representative — Mozilla indicated it would schedule closure for Friday, 20-Sept-2024 unless there were questions or issues.
Participants
Sectigo Mozilla representative
Similar Local Cases
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 100% similar
Sectigo: Missing character in subject:organizationName attribute value
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 79% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 77% similar
Sectigo: Incorrect JOI for federal credit unions
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 75% similar
Sectigo: Incorrect OCSP responses
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 68% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 68% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1718785 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2024-06-30 · 68% similar
Sectigo: 2020 failure to respond to CPRs discovered
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 67% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action