← Sectigo cases
Bugzilla #1912225
Certificate Problem Report
Sectigo: HTML encoded characters in subject attribute values
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo addressed a Certificate Problem Report regarding misissued certificates that contained HTML encoded characters in the subject:organizationName attribute. The issue was identified on August 6, 2024, leading to the revocation of 11 affected certificates. A root cause analysis revealed that an integration issue with their pre-issuance linter caused the misissuance. The problem was resolved with a successful deployment of updates to their systems, and all action items were completed by September 17, 2024.
Chronology
- Received Certificate Problem Report regarding misissued certificate.
- Revocation of the initial reported certificate.
- Completion of all action items and successful deployment.
Participants
Martijn Katerbarg
Ben Wilson
External References
Similar Local Cases
Sectigo: Missing character in subject:organizationName attribute value
Sectigo: Non-existent hostname in CDP and AIA URLs
Sectigo: S/MIME certificates with (null) string value in subject attributes
Sectigo: Temporary unavailability for subset of CRLs
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
Sectigo: Premature disabling of CRL generation for an inactive CA
Sectigo: Late revocation for incomplete Subject organizationName