Re: [exim/exim] [Bug]: GNUTLS certificate validation incompatible with certificates lacking a commonName attribute (Issue #3215)

"Adam D. Barratt via Exim-dev" <[email protected]> Wed, 15 Apr 2026 19:06:55 +0100
Newsgroups gmane.mail.exim.devel
Message-ID <cd4ce93e42dfa5c1694a3a7f4db9f49b435981ed.camel@adam-barratt.org.uk>
On Wed, 2026-04-15 at 18:32 +1000, Viktor Dukhovni via Exim-dev wrote:
> On Wed, Apr 15, 2026 at 06:30:36AM +0100, adsbarratt via Exim-dev
> wrote:
> 
> > As was pointed out in a follow-up on exim-dev, one other difference
> > is
> > that the exim.org certificate has a Subject DN:
> > 
> > 0 s:CN=cumin.exim.org
> > 
> > whereas my test setup does not:
> > 
> > 0
> > s:                                                                 
> >                                    
> >   i:C = US, O = Let's Encrypt, CN =
> > YR2                                                                
> 
> For the record, a technical nit, both have a subject DN (which is a
> non-optional element of the X.509 TBS structure), but the second
> subject DN is an empty sequence.  So the DN has no rDNs, and in so
> particular no "CN" element.

ACK. Apologies for the imprecision.

Regards,

Adam

-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
##   [email protected]
## Exim details at https://www.exim.org/
## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki