You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If subject
naming information is present only in the subjectAltName extension
(e.g., a key bound only to an email address or URI), then the subject
name MUST be an empty sequence and the subjectAltName extension MUST
be critical.
However, currently rcgen hardcodes SANs as non-critical:
Per https://tools.ietf.org/html/rfc5280#section-4.1.2.6 :
However, currently rcgen hardcodes SANs as non-critical:
rcgen/rcgen/src/certificate.rs
Line 502 in cd88a39
It would be nice to have this either automatically detect empty subject and mark it as critical, or have a way to indicate the extension as critical.
If I understand right, the only way to do this currently would be with a custom extension which seems like a lot of work.
I am willing to work on a fix for this
The text was updated successfully, but these errors were encountered: