[Servercert-wg] SC48 and case sensitivity of CN and SAN value encoding

Corey Bonnell Corey.Bonnell at digicert.com
Fri Aug 6 12:45:14 UTC 2021


A question on the GitHub PR for SC48 [1] pointed out that the language
surrounding acceptable encoding of CN values is not clear whether case
mismatches of the SAN dNSName and CN value are allowed. The conclusion of
that discussion is that at least one Root Program will view such case
mismatches as mis-issuance. It appears that there may be several CAs
impacted by this, so I wanted to alert the group in case this is unexpected
for those CAs.





[1] https://github.com/cabforum/servercert/pull/285#discussion_r683444000


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20210806/9dfe299f/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4990 bytes
Desc: not available
URL: <http://lists.cabforum.org/pipermail/servercert-wg/attachments/20210806/9dfe299f/attachment.p7s>

More information about the Servercert-wg mailing list