Re: RFC 5280 and example of a self signed end-entity certificate?

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Jeffrey Walton <[email protected]> writes:

>That creates a malformed server certificate because the hostname is placed in
>the CN and not the SAN, it uses SHA1 by default, and it fails to use UTF-8
>strings by default. At minimum, its not following best practices and using
>deprecated methods.

It depends on what you define as "malformed".  Everything puts the server name
in the DN, you don't need UTF-8 strings in most cases, and whether you use
SHA-1 in a self-signed EE cert is a matter of preference (it's not like
someone is going to have to break SHA-1 to create a fake cert)...

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.