I added a sub-bullet to the "DNS names in SANs" item with a link to the
draft.
* See also section 4.4.4 of IETF Draft spec on TLS Server ID Checking.
Thanks,
Kathleen
Indeed. Unfortunately that draft is beginning to be used as a reason to
continue using DNS names in Subject:CN.
I think it would be better if the final version of it were to seriously
obsolete that practice in the "SHOULD accept" - "MUST NOT produce" manner.
That's where we would like to end up, and we tried to move in that
direction with this RFC. I expect the RFC to be obsoleted with an
revised spec in the next few years, and at that time I hope that we can
say "MUST NOT put the DNS domain name in the Subject".
Peter
--
Peter Saint-Andre
https://stpeter.im/
However I believe compliance should be first enforced in the software,
meaning that they should stop checking for it in the common name field.
Only after that CAs can happily refrain from including them in the CN,
otherwise their certs will not work.
And even Apache still checks for the common name and omits a warning if
the that doesn't match the configured host.
--
Regards
Signer: Eddy Nigg, StartCom Ltd.
XMPP: star...@startcom.org
Blog: http://blog.startcom.org/
Twitter: http://twitter.com/eddy_nigg
Yes, I think in general the leadership here needs to come from the
community of server (often web) developers, client (often browser)
developers, and certification authorities. The spec that Jeff and I
worked on tried to capture the best current practices, but publishing a
spec doesn't change the reality on the ground.