The Windows Client Certificate Enrollment Protocol [MS-WCCE] defines a sanitizing mechanism e.g. for common names in section 1.3.2.4 and section 3.1.1.4.1.1. After I gave my favorite search engine a try and ensured there is no built-in function to call I built my own. Here it is: