Re: [exim/exim] [Bug]: GNUTLS certificate validation incompatible with certificates lacking a commonName attribute (Issue #3215)
Viktor Dukhovni via Exim-dev <[email protected]> Wed, 15 Apr 2026 18:32:50 +1000
| Newsgroups | gmane.mail.exim.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Apr 15, 2026 at 06:30:36AM +0100, adsbarratt via Exim-dev wrote:
> As was pointed out in a follow-up on exim-dev, one other difference is
> that the exim.org certificate has a Subject DN:
>
> 0 s:CN=cumin.exim.org
>
> whereas my test setup does not:
>
> 0 s:
> i:C = US, O = Let's Encrypt, CN = YR2
For the record, a technical nit, both have a subject DN (which is a
non-optional element of the X.509 TBS structure), but the second subject
DN is an empty sequence. So the DN has no rDNs, and in so particular no
"CN" element.
--
Viktor. 🇺🇦 Слава Україні!
--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## [email protected]
## Exim details at https://www.exim.org/
## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki