Sectigo: HTML encoded characters in subject attribute values
Sectigo received a Certificate Problem Report (CPR) on 2024-08-06 about a single certificate whose subject:organizationName attribute contained an HTML encoded “&” entity. In its investigation, Sectigo determined the certificate was misissued because the subject contained the HTML entity string “\&” instead of the “&” character. Sectigo reported that 11 certificates were affected, covering issuance dates from 2023-07-13 to 2024-03-05. Sectigo scheduled revocation for the initially reported certificate on 2024-08-11 and also created a revocation event for 10 additional misissued certificates on 2024-08-11. Sectigo implemented an update to its pkimetal ftfy integration (pushed to pkimetal) and later completed analysis of its pre-issuance ftfy integration, concluding the root cause differed from the issue already fixed in pkimetal. The bug was resolved as FIXED, and Sectigo requested closure after completing remaining action items, with Mozilla scheduling closure for 2024-09-20.
- Sectigo received a CPR reporting a certificate whose subject:organizationName contained an HTML-encoded “&” entity string.
- Sectigo revoked the initially reported certificate and 10 additional discovered misissued certificates.
- Sectigo completed remaining action items after a planned deployment.
- Sectigo — Sectigo posted a preliminary incident report stating it was investigating the CPR and that the reported certificate was scheduled for revocation on 2024-08-11.
- Sectigo — Sectigo posted the incident report confirming the certificate was misissued, identifying 11 affected certificates, describing its investigation and revocation scheduling, and noting an update implemented for the pkimetal ftfy integration.
- Sectigo — Sectigo corrected an editorial mistake in the affected-certificate details and provided the corrected crt.sh links.
- Sectigo — Sectigo requested a next update for 2024-09-15 based on due dates in its action items.
- Sectigo — Sectigo announced it was still on track to complete action items through a scheduled deployment that weekend.
- Sectigo — Sectigo stated the planned deployment was completed successfully, all remaining action items were completed, and it requested closing the bug.
- Mozilla representative — Mozilla indicated it would schedule closure for Friday, 20-Sept-2024 unless there were questions or issues.