#1019·openvpn

验证仅针对 SAN 的 TLS 证书的错误

作者: jouir创建于 2026年4月21日更新于 2026年8月20日
标签enhancementnon-trivial changefeature

Description

Hi folks, I use certbot and step-ca to manage a private PKI. I'm trying to use those certificates for OpenVPN instead of using manual commands for generation and renewal. According to the RFC 2818:

If a subjectAltName extension of type dNSName is present, that MUST be used as the identity. Otherwise, the (most specific) Common Name field in the Subject field of the certificate MUST be used. Although the use of the Common Name is existing practice, it is deprecated and Certification Authorities are encouraged to use the dNSName instead.

内容来源: OpenVPN/openvpn