DigiCert: Truncation of Registration Number
This case describes DigiCert certificates where the Registration Number field was truncated to 64 characters instead of rejecting the issuance request when the registration number exceeded the allowed length. DigiCert said it discovered the issue during a regular audit of its certificates, finding a registration number that did not fit an expected pattern and determining that the certificate had a truncated registration number. DigiCert reported that it found two affected certificates (issued 07/28/2020 and 08/23/2021) and that the CA system issued the certificate with a truncated value rather than rejecting the request due to a system limitation. DigiCert stated that engineering applied a change on 08/27/2021 to reject publicly-trusted signing requests when submitted information exceeds the length allowed by RFC5280, aligning the Registration Number handling with other fields. DigiCert also stated it scheduled revocation for five days from confirmation of the issue and later discussed additional remediation in the RA system, including revoking three instances identified during its review and adding warnings to RA staff and a warning system for staff alerts. Mozilla indicated it would close the bug on 17-Sept-2021, and the bug is marked RESOLVED with resolution FIXED.
- DigiCert identified that a certificate was issued with a Registration Number truncated to 64 characters after the registration number exceeded 64 characters.
- DigiCert completed a comprehensive sweep and found two certificates with the truncated Registration Number condition.
- DigiCert applied a CA-side change to reject signing requests with fields exceeding the RFC5280 length limit instead of truncating.
- DigiCert provided additional details on RA/CA root causes and remediation, including revocations and warning updates.
- Mozilla closed the bug after confirming no further questions were needed.
- DigiCert — Jeremy Rowley reported that an audit found a Registration Number not matching expectations, that two certificates were affected by truncation, and that DigiCert investigated and implemented a change to reject over-length signing requests.
- Mozilla representative — Ben Wilson asked whether other CAs could be better supported for similar long-source handling and whether DigiCert had remaining remediation tasks before closing.
- DigiCert — Jeremy Rowley described RA and CA reviews, identified additional improper truncation instances to be revoked under the five-day rule, and outlined warning/remediation steps before offering to close the bug.
- Mozilla representative — Ben Wilson scheduled closure on 17-Sept-2021 unless further questions were needed.
- Community commenter — Ryan Sleevi requested deeper analysis of the facts and mitigation, expressing concerns about semantic correctness and controls for EV-related fields.
- DigiCert — Jeremy Rowley responded with explanations of root causes, field expectations, and how the CA/RA systems handled registration number and other truncated values.
- DigiCert — Jeremy Rowley stated there were no additional updates.
- Mozilla representative — Ben Wilson said he would close the bug on Friday, 17-Sept-2021 unless additional questions remained.