• V
    Limit scope of CN name constraints · d02d80b2
    Viktor Dukhovni 提交于
    Don't apply DNS name constraints to the subject CN when there's a
    least one DNS-ID subjectAlternativeName.
    
    Don't apply DNS name constraints to subject CN's that are sufficiently
    unlike DNS names.  Checked name must have at least two labels, with
    all labels non-empty, no trailing '.' and all hyphens must be
    internal in each label.  In addition to the usual LDH characters,
    we also allow "_", since some sites use these for hostnames despite
    all the standards.
    Reviewed-by: NMatt Caswell <matt@openssl.org>
    Reviewed-by: NTim Hudson <tjh@openssl.org>
    d02d80b2
goodcn1-cert.pem 1.3 KB