验证仅针对 SAN 的 TLS 证书的错误
作者: jouir创建于 2026年4月21日更新于 2026年8月20日
标签enhancementnon-trivial changefeature
Description
Hi folks, I use certbot and step-ca to manage a private PKI. I'm trying to use those certificates for OpenVPN instead of using manual commands for generation and renewal. According to the RFC 2818:
If a subjectAltName extension of type dNSName is present, that MUST be used as the identity. Otherwise, the (most specific) Common Name field in the Subject field of the certificate MUST be used. Although the use of the Common Name is existing practice, it is deprecated and Certification Authorities are encouraged to use the dNSName instead.
内容来源: OpenVPN/openvpn