Salz, Rich via openssl-users <> wrote:
    > Putting the DNS name in the CN part of the subjectDN has been
    > deprecated for a very long time (more than 10 years), although it
    > is still supported by many existing browsers. New certificates
    > should only use the subjectAltName extension.

Fair enough.

It seems that the "openssl ca" mechanism still seem to want a subjectDN
defined.  Am I missing some mechanism that would let me omit all of that?  Or
is a patch needed to kill what seems like a current operational requirement?

]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        |    IoT architect   [
]        |   ruby on rails    [

Attachment: signature.asc
Description: PGP signature

openssl-users mailing list
To unsubscribe:

Reply via email to