View Issue Details

IDProjectCategoryView StatusLast Update
000811110000-012: DiscoverySpecpublic2022-07-19 15:43
ReporterMartin Regen Assigned ToJim Luth  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionno change required 
Summary0008111: CA/B Forum sunset organizationalUnitName (OU) relative distinguished name
Description

An industry group called the CA/B Forum (Certificate Authority / Browser) oversees the Internet PKI ecosystem. The CA/B Forum has passed a new rule, ballot SC47, that sunsets the organizationalUnitName (OU) relative distinguished name.

Ensure there is no reference in the spec to OU=, also that sample codes don't use it.

Implication may be that commercial PKI silently strip out the OU= names when issueing certs, it can lead to functional issues when apps load the cert based on subject name, which may then be different than the original configuration, so OU should not be used.

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Jim Luth

2022-07-19 15:43

administrator   ~0017152

Spec is clear that the subject can be changed by the CA. No change required in the spec.

Issue History

Date Modified Username Field Change
2022-07-17 05:43 Martin Regen New Issue
2022-07-19 15:43 Jim Luth Assigned To => Jim Luth
2022-07-19 15:43 Jim Luth Status new => closed
2022-07-19 15:43 Jim Luth Resolution open => no change required
2022-07-19 15:43 Jim Luth Note Added: 0017152