← D-TRUST cases
Bugzilla #1563772
Certificate Problem Report
D-TRUST: Precertificate OU > 64 Characters
RESOLVED
FIXED
D-TRUST
AI Summary
D-TRUST identified an issue where the Organizational Unit (OU) field of precertificates exceeded the maximum length of 64 characters. This was discovered during an internal quality assurance check on July 5, 2019, leading to immediate corrective actions including stopping issuance and investigating the error. The root cause was determined to be a failure in the X.509 controls for precertificates, which had not effectively checked the field length in this specific case. D-TRUST has since implemented additional monitoring and control measures to prevent similar issues in the future.
Chronology
- Internal quality assurance noticed the error
- Issuing stopped
- Revocation of defective pre-certificates
- Final incident report published
Participants
Enrico Entschew
Ryan Sleevi
Kim Nguyen
External References
Similar Local Cases
D-TRUST: incorrectly formatted businessCategory entry
D-TRUST: Non-BR-Compliant Certificate Issuance
D-TRUST: syntax error in one tls certificate
QuoVadis: BR Error - san dns name starts with period
Sectigo: "Some-State" in stateOrProvinceName
Camerfirma: Unrevocation of MULTICERT SSL Certification Authority 001 certificate
Asseco DS / Certum: commonName not from subjectAltName entries
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant OCSP Responders