> > [alt_names] DNS.1 = hkps.pool.sks-keyservers.net DNS.2 = > > *.pool.sks-keyservers.net DNS.3 = pool.sks-keyservers.net DNS.4 = > > keys.niif.hu > > This part is unnecessary, the SANs are added by me the input is > discarded when generating the certificate. So you can simplify this to
Anyway the result is this: $ openssl x509 -in hkps.pool.sks-keyservers.net.crt -noout -text Certificate: Data: Version: 3 (0x2) Serial Number: 94 (0x5e) Signature Algorithm: sha256WithRSAEncryption Issuer: C=NO, ST=Oslo, O=sks-keyservers.net CA, CN=sks-keyservers.net CA Validity Not Before: May 16 11:26:58 2015 GMT Not After : May 15 11:26:58 2016 GMT Subject: C=HU, O=NIIF Institute, CN=keys.niif.hu [...] X509v3 Subject Alternative Name: DNS:hkps.pool.sks-keyservers.net, DNS:*.pool.sks-keyservers.net, DNS:pool.sks-keyservers.net, DNS:keys.niif.hu [...] Gabor _______________________________________________ Sks-devel mailing list Sks-devel@nongnu.org https://lists.nongnu.org/mailman/listinfo/sks-devel