Re: distinguished name order

Jochen Bern <[email protected]> Wed, 30 Jul 2025 09:54:09 +0200
Newsgroups gmane.comp.encryption.openssl.user
Organization Binect GmbH
Message-ID <[email protected]>
On 30.07.25 00:19, Mike wrote:
[about ordering of elements within the DN]
> Is this correct as is?  Is it a known issue?  The manual pages don't really
> talk about it.  I'm not familiar with the historical LDAP usages.

All talk about *current* standards aside, if you plan to run things in 
the long term, you'll need to be prepared to see these standards change. 
The current two *nominal* root CA certs of our company both have 
ultimately been created with OpenSSL (of their time), and lo:

> $ ChainCat RootCA-?/root_ca.crt
> 
> ### RootCA-A/root_ca.crt ###
> 
> CERTIFICATE:
>         subject=CN=Root CA, O=pawisda systems GmbH, L=Weiterstadt, ST=Hessen, C=DE
>         issuer=CN=Root CA, O=pawisda systems GmbH, L=Weiterstadt, ST=Hessen, C=DE
>         notBefore=Oct 18 22:00:00 2012 GMT
>         notAfter=Oct  5 22:00:00 2028 GMT
> 
> ### RootCA-B/root_ca.crt ###
> 
> CERTIFICATE:
>         subject=C=DE, ST=Hessen, L=Weiterstadt, O=Binect GmbH, CN=Root CA - B, [email protected]
>         issuer=C=DE, ST=Hessen, L=Weiterstadt, O=Binect GmbH, CN=Root CA - B, [email protected]
>         notBefore=Oct  7 16:19:21 2020 GMT
>         notAfter=Sep 26 16:19:21 2036 GMT

Kind regards,
-- 
Jochen Bern
Systemingenieur

Binect GmbH

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/acba6d99-7e57-4d2f-ad1f-66a965abc3f1%40binect.de.
smime.p7s (application/pkcs7-signature, 4.2 KB) - not displayed