← DigiCert cases
Bugzilla #1556906
Certificate Problem Report
DigiCert: Apple: Non-compliant Common Name Length
RESOLVED
DigiCert
AI Summary
DigiCert reported an incident involving the issuance of certificates with Common Names exceeding the 64-character limit, a violation of RFC 5280. The issue was discovered during a code review on May 15, 2019, leading to the revocation of two certificates and a subsequent investigation. A software fix was deployed on May 22, 2019, to enforce the character limit, and a comprehensive gap analysis was conducted to ensure compliance with relevant standards. The case has been resolved with all necessary remediation steps completed.
Chronology
- Code review identified non-compliance with CN length.
- Compliance team notified of the issue.
- Software fix deployed to enforce CN length.
- Gap analysis completed, confirming compliance.
Participants
certification_authority@apple.com
ryan.sleevi@gmail.com
External References
Similar Local Cases
Apple: EV Certificate Approver Authorization
Apple: OCSP responders return responses with incorrect issuer
Apple: OCSP availability 2020-11-12
DigiCert: Undisclosed CAs -Federated Trust CA-1
DigiCert: IP in dnsName
DigiCert: Underscores - Discover
DigiCert: Invalid Country Code Issuance
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs