client certs with no subjectName only SAN

Salz, Rich rsalz at akamai.com
Thu Aug 15 20:13:19 UTC 2019


subjectAltName is rarely marked as critical; sec 4.2.1.6 of PKIX says "SHOULD mark subjectAltName as non-critical"

I can believe that OpenSSL doesn't support empty subjectName's.  An empty one, with no relative disintuished name components, is not the same as not present.




More information about the openssl-users mailing list