Re: RFC 5280 and example of a self signed end-entity certificate?
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Jeffrey Walton <[email protected]> writes: >That creates a malformed server certificate because the hostname is placed in >the CN and not the SAN, it uses SHA1 by default, and it fails to use UTF-8 >strings by default. At minimum, its not following best practices and using >deprecated methods. It depends on what you define as "malformed". Everything puts the server name in the DN, you don't need UTF-8 strings in most cases, and whether you use SHA-1 in a self-signed EE cert is a matter of preference (it's not like someone is going to have to break SHA-1 to create a fake cert)... Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix