← DigiCert cases
Bugzilla #1727963
Certificate Problem Report
DigiCert: Truncation of Registration Number
RESOLVED
DigiCert
AI Summary
DigiCert identified an issue where registration numbers for certain certificates were truncated to 64 characters instead of being rejected when exceeding the maximum length. This was discovered during an internal audit, leading to an investigation that revealed two affected certificates. The CA has since implemented a fix to ensure that any signing requests with overly long registration numbers are rejected, preventing future occurrences of this issue.
Chronology
- Long registration number pattern added and disclosed.
- Compliance team conducted a system sweep and identified two certificates with truncated registration numbers.
- Patch applied to reject signing requests with overly long registration numbers.
Participants
Jeremy Rowley
Ben Wilson
External References
Similar Local Cases
Digicert: Government Entity listed instead of registration number
Digicert: SMIME certificate with unvalidated information
DigiCert: Random value in CNAME without underscore prefix
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: OCSP responder returning invalid responses
DigiCert: Failure to revoke key-compromised certificates within 24 hours
DigiCert: Certificate Issues Identified on the Mailing List