For publicly trusted certificates, industry standards (baseline requirements and RFC 5280) require data entries meet certain criteria. Violating these standards when ordering a certificate prevents a Certificate Authority (CA) from issuing the certificate.
For publicly trusted certificates, the organization unit value is not a required value (field). According to baseline requirements, Certificate Authorities (CAs) are only required to validate the organization unit value, when a value is provided. If you leave this field blank (do not provide an organization unit value), CAs are instructed not to include the field in the certificate.
Baseline requirements also prohibit this value from being or appearing to be "junk" data or indicators of non-applicability (na, ?, etc.), which helps keep certificates smaller. By keeping certificates smaller, this ensures TLS remains accessible to a greater range of users and site operators.
The list below contains some of the characters that if entered by themselves in the organization unit field do not represent a valid organization unit value.
If you only put a hyphen in the organization unit field, a CA will be unable to validate the value. However, if you enter an organization name that includes a hyphen in it (for example, Dev-Ops), this hyphen does not prevent a CA from validating your organization unit value.
For publicly trusted certificates, we cannot allow these values (data entries) to exceed the 64-maximum character limit, including spaces:
For publicly trusted certificates, we can no longer allow use of underscores ( _ ) in:
As of October 1, 2018, we can only issue certificates for domains and subdomains using:
Currently, you can include underscores in other certificate values, such as organization unit and organization names. However, the use of the underscore in these values is being reevaluated. Industry standards may change and require you to remove the underscores from those values too.