India Government's official Website for managing public retirement fund, NPS, eNPS does this. Password need to be changed every 90 days, of max 14 characters length, but no where documented. On password change page, it will silently accept your any 14+ length password & will truncate it to 14. Then you try to login with your actual password, it gives error, Wrong Password.
In the U. S., Washington state's initial rollout of their ACA site did that. Gave it a big, long >20 char password, it created the account, go to log in and...
How did I figure out what was going on? They would happily email your password in plain text. </facepalm>
It also didn't notify me that it didn't allow such passwords, it just went right ahead and created an account it was impossible to log in to.
Thankfully, I was able to reset the password to one which is far unsafer.
Well done everyone.