Limit scope of CN name constraints
Don't apply DNS name constraints to the subject CN when there's a least one DNS-ID subjectAlternativeName. Don't apply DNS name constraints to subject CN's that are sufficiently unlike DNS names. Checked name must have at least two labels, with all labels non-empty, no trailing '.' and all hyphens must be internal in each label. In addition to the usual LDH characters, we also allow "_", since some sites use these for hostnames despite all the standards. Reviewed-by: NMatt Caswell <matt@openssl.org> Reviewed-by: NTim Hudson <tjh@openssl.org>
Showing
test/certs/badcn1-cert.pem
0 → 100644
test/certs/badcn1-key.pem
0 → 100644
test/certs/goodcn1-cert.pem
0 → 100644
test/certs/goodcn1-key.pem
0 → 100644
想要评论请 注册 或 登录