Bug ID 556782: Subject Alternative Name is case sensitive

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
11.5.3, 11.5.3 HF1, 11.5.3 HF2, 11.5.4, 11.5.4 HF1, 11.5.4 HF2, 11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 11.6.1, 11.6.1 HF1, 12.0.0, 12.0.0 HF1, 12.0.0 HF2, 12.0.0 HF3, 12.0.0 HF4

Fixed In:
12.1.0, 11.6.1 HF2, 11.5.4 HF3

Opened: Nov 07, 2015

Severity: 3-Major

Symptoms

Wrong certificate may be returned when request Subject Name or certificate Subject Alternative Name contains mixed case.

Impact

Wrong certificate may be returned leading to security warnings.

Conditions

Subject Name contains mixed case or the Subject Alternative Name contains mixed case.

Workaround

In most cases the domain in the Subject Name and the domain(s) in the Subject Alternative Name are sent in all lowercase. If the Subject Alternative Name contains mixed case, regenerate and re-sign the certificate/public key with lowercase Subject Alternative Name domains.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips