X509 主题备用名称 (subjectAltName) IP 地址字段

Pno*_*tNP 5 openssl google-chrome chromium x509

X509v3 可以在扩展中包含IP地址字段subject Alternative Name

  1. 作为验证服务器身份的应用程序,IP地址字段应该如何验证?
  2. DNS 名称和 IP 地址是否都存在?是否存在对其中一种的偏好?
  3. 字段有什么用dirName

Pno*_*tNP 6

我之前读过 RFC 2818,但一定错过了这一部分。

In some cases, the URI is specified as an IP address rather than a
hostname. In this case, the iPAddress subjectAltName must be present
in the certificate and must exactly match the IP in the URI.
Run Code Online (Sandbox Code Playgroud)