DigiCert: Invalid Characters in S/MIME Subject Fields
DigiCert reported a compliance issue involving the issuance of 21 S/MIME certificates containing invalid characters (accents) in the SubjectDN and SAN fields. This problem arose due to a misconfiguration in the linting process on their legacy QuoVadis system, which allowed these certificates to be issued despite the errors being logged. DigiCert halted S/MIME issuance from the affected legacy operations and revoked all impacted certificates within the required timeframe. They have since corrected the linting configuration and are committed to maintaining compliance until the legacy system is fully deprecated by March 31, 2025.
- Issue reported via post-issuance linting, additional research kicked off.
- All affected certificates revoked.
- Incident Report Closure Summary provided.
- DigiCert — There was a bug in the script that integrates pkilint into our legacy European operations, resulting in some certificates with invalid characters being issued.
- Sectigo — Questioned why the issuing platform allowed the issuance of these certificates.
- DigiCert — Provided a closure summary detailing the incident and remediation steps.