← Krajowa Izba Rozliczeniowa S.A. (KIR) cases
Bugzilla #1532112
Ca Certificate Compliance
KIR S.A.: organizationName longer than 64 characters
RESOLVED
DUPLICATE
Krajowa Izba Rozliczeniowa S.A. (KIR)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case was raised because the reporter found KIR-issued certificates whose organizationName field exceeded 64 characters. The reporter provided examples via crt.sh links for specific certificate IDs and noted the issue as an organizationName length problem. A Mozilla CA Program participant (w**********r@fastly.com) marked the bug as a duplicate of bug 1495497. The bug’s resolution is listed as DUPLICATE, and the thread does not describe any CA remediation or corrective action beyond the duplicate marking. No additional policy or technical remediation steps are stated in the provided comments.
Chronology
- A report was filed about KIR-issued certificates having organizationName longer than 64 characters.
- The bug was marked as a duplicate of another CA Program bug.
Thread Activity
- Lebihan representative — Reported that KIR-issued certificates have organizationName longer than 64 characters and linked examples on crt.sh.
- Fastly representative — Marked the bug as a duplicate of bug 1495497.
Participants
Lebihan representative
Fastly representative
Kir representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
KIR S.A.: Invalid organizationName
KIR S.A.: Many certificates with OCSP Unknown
KIR S.A.: CN domain not in SAN
KIR S.A.: Misissuance - missing OCSP AIA, Validity > 825 days
KIR: Intermediate CA - SZAFIR Trusted CA4 - Certificate Policies extension - non-compliance
GDCA: Misissuance of certificates with IP address
DigiCert: TERENA: Insufficient validation of organizationalUnitName
Microsoft DSRE PKI: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request