User can't configure a Common Name (CN) for certificate object. CN field is 'greyed out' (not editable) when trying to add a certificate to an application.
A parent policy has "User Provided CSR" as part of the CSR Handling section. The CN cannot be filled in on the Director side because the CSR has the CN already filled in as part of the request.
Either change the "User Provided CSR" to "Service Generated CSR" in the CSR Handling section, which will allow you to fill in the CN, or if the security policy requires user provided CSR, don't modify anything. Only ensure that the application where the CSR is generated requires a CN.