DigiCert: no subject alternative name (SAN) in Siemens certificates
The bug reports that DigiCert observed recent certificates in a chain involving the Baltimore CyberTrust Root and Siemens issuing CAs that were missing the Subject Alternative Name (SAN) extension. The initial report describes the certificate subject details and notes the absence of the SAN extension. Verizon Business asked for an action plan to resolve the issue after reiterating proper certificate content requirements to its OmniRoot subordinate customer. DigiCert later stated that Siemens is no longer issuing certificates at all from the Baltimore root, and that the issue is fixed because the root is only active to support existing digital certificates. DigiCert said it plans to revoke the intermediate once existing certificates expire, and asked whether Mozilla would like all certificates missing SANs revoked. Mozilla declined to request revocation of all valid certificates with the existing problem, and the bug was closed as fixed.
- A report was filed that certain Siemens-issued certificates in the Baltimore CyberTrust Root chain lacked the Subject Alternative Name (SAN) extension.
- Verizon Business requested an action plan from DigiCert/Siemens to resolve the missing-SAN issue.
- DigiCert indicated the issue should be fixed.
- DigiCert stated Siemens stopped issuing certificates from the Baltimore root and described a plan to revoke the intermediate after existing certificates expire.
- Mozilla closed the bug as fixed without requesting revocation of all valid certificates missing SANs.
- Roeckx representative — Reported recent certificates missing the subject alternative name extension in a chain from the Baltimore CyberTrust Root to Siemens issuing CAs.
- Mozilla representative — Referred to another “no-SAN” bug.
- Verizonbusiness representative — Said they were reiterating proper certificate content requirements to an OmniRoot subordinate customer and requested an action plan to resolve the issue.
- DigiCert — Indicated the issue “should be fixed.”
- Mozilla representative — Asked for clarification of what “fixed” meant (e.g., whether bad certs were revoked or issuance process corrected).
- DigiCert — Stated Siemens stopped issuing certificates from the Baltimore root; said the root supports only existing certificates and they plan to revoke the intermediate after those expire, and asked whether all missing-SAN certs should be revoked.
- Community commenter — Noted that new certificates chain up to QuoVadis Root CA 2 G3 via intermediates.
- Mozilla representative — Said revoking all valid certs missing SANs was not necessary and closed the bug as fixed.