Re: Syntax of Subject Alternative Names field in a certificate
Denis <[email protected]> Tue, 16 Apr 2024 18:52:13 +0200
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Andreas,
The general syntax is here:
https://www.alvestrand.no/objectid/2.5.29.17.html
It has been originally defined by ISO / ITU-T, i.e., not by the IETF.
Denis
> Hi Andreas -
>
> You appear to be asking about how to make Openssl issue a cert with an
> SAN. That's not a topic for this list.
>
> This list is about IETF standards in the Public Key Infrastructure
> field of use. If you have a question about the ASN1 that goes into
> making an SAN OtherName, that would be more appropriate for this list.
>
> I'd suggest referring your questions to the OpenSSL community, or
> going to the repository and reading the code directly.
>
> Good luck - Mike
>
>
> On 4/16/2024 8:12 AM, Andreas Maier wrote:
>>
>> Hi, I am trying to understand what the syntax is for the string value
>> of the Subject Alternative Names field, particularly when it contains
>> multiple entries.
>>
>> I was hopeful to find that in
>> https://datatracker.ietf.org/doc/html/rfc5280 which as a section
>> 4.2.1.6
>> <https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.6>
>> “Subject Alternative Name” but I could not get that out of the syntax
>> description in there. I can find examples which seem to suggest it is
>> a comma-separated list of items, each of which has a type indicator
>> (e.g. “DNS”), as in:|DNS:{hostname1},IP:{ip2},email:{email},URI:{uri4}|
>>
>> Some sources for the examples:
>>
>> * https://www.openssl.org/docs/man1.0.2/man5/x509v3_config.html
>> * https://support.hpe.com/hpesc/public/docDisplay?docId=sf000094754en_us&docLocale=en_US&page=index.html
>> <https://support.hpe.com/hpesc/public/docDisplay?docId=sf000094754en_us&docLocale=en_US&page=index.html>
>> * https://www.linode.com/docs/guides/using-openssls-subjectaltname-with-multiple-site-domains/ use:
>>
>> Where is the syntax of the Subject Alternative Names field documented
>> in an RFC?
>> Are the type indicators mandatory or optional?
>>
>> Kind regards,
>>
>> Andy
>>
>>
>> _______________________________________________
>> pkix mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/pkix
>
>
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix
_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix