[openssl-users] Signing a csr with subjectAltName using x509 command

Mauro Romano Trajber trajber at gmail.com
Wed Jan 13 17:37:10 UTC 2016


I created a CSR with subjectAlternativeNames:

$ openssl req -noout -in my.csr -text
  Requested Extensions:
            X509v3 Subject Alternative Name:
                IP Address:, DNS:www.example.com

But when I try to sign it using my own CA using the x509 command this data
is removed

$ openssl x509 -req -in my.csr -CA my-ca.cert -CAkey my-ca.key
-CAcreateserial -out my.cert -days 3650

Do you know how can I preserve this data on my certificate?

