← DigiCert cases
Bugzilla #1556906 · Certificate Problem Report
DigiCert: Apple: Non-compliant Common Name Length
DigiCert · RESOLVED
AI Summary
DigiCert reported an incident involving the issuance of certificates with Common Names exceeding the 64-character limit, a violation of RFC 5280. The issue was discovered during a code review on May 15, 2019, leading to the revocation of two certificates and a subsequent investigation. A software fix was deployed on May 22, 2019, to enforce the character limit, and a comprehensive gap analysis was conducted to ensure compliance with relevant standards. The case has been resolved with all necessary remediation steps completed.
Chronology
- Code review identified non-compliance with CN length.
- Compliance team notified of the issue.
- Software fix deployed to enforce CN length.
- Gap analysis completed, confirming compliance.
Participants
certification_authority@apple.com
ryan.sleevi@gmail.com
External References
Similar Local Cases
DigiCert: Undisclosed CAs -Federated Trust CA-1
DigiCert: IP in dnsName
DigiCert: Underscores - Discover
DigiCert: Invalid Country Code Issuance
GoDaddy: Precertificates incorrectly logged to DigiCert SCT Logs
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: P-384,ecdsa-with-SHA512 Certificates
DigiCert: Underscores - Canadian Imperial Bank of Commerce