> > [alt_names] DNS.1 = hkps.pool.sks-keyservers.net DNS.2 =
> > *.pool.sks-keyservers.net DNS.3 = pool.sks-keyservers.net DNS.4 =
> > keys.niif.hu
> 
> This part is unnecessary, the SANs are added by me the input is
> discarded when generating the certificate. So you can simplify this to

Anyway the result is this:

$ openssl x509 -in hkps.pool.sks-keyservers.net.crt -noout -text
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 94 (0x5e)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=NO, ST=Oslo, O=sks-keyservers.net CA, CN=sks-keyservers.net CA
        Validity
            Not Before: May 16 11:26:58 2015 GMT
            Not After : May 15 11:26:58 2016 GMT
        Subject: C=HU, O=NIIF Institute, CN=keys.niif.hu
[...]
            X509v3 Subject Alternative Name: 
                DNS:hkps.pool.sks-keyservers.net, 
DNS:*.pool.sks-keyservers.net, DNS:pool.sks-keyservers.net, DNS:keys.niif.hu
[...]

Gabor

_______________________________________________
Sks-devel mailing list
Sks-devel@nongnu.org
https://lists.nongnu.org/mailman/listinfo/sks-devel

Reply via email to