client certs with no subjectName only SAN

Salz, Rich rsalz at
Thu Aug 15 20:13:19 UTC 2019

subjectAltName is rarely marked as critical; sec of PKIX says "SHOULD mark subjectAltName as non-critical"

I can believe that OpenSSL doesn't support empty subjectName's.  An empty one, with no relative disintuished name components, is not the same as not present.

More information about the openssl-users mailing list