>> Another requirement is that a TLS server certificate shall have its identity (FQDN) in the SAN extension. Use of the commonName attribute has been deprecated long ago. > Where is this documented ? Might be of interest : https://stackoverflow.com/questions/5935369/ssl-how-do-common-names-cn-and-subject-alternative-names-san-work-together -- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users