4 ms·
This is not a valid certificate. See https://tools.ietf.org/html/rfc6125#section-6.4.3 https://tools.ietf.org/html/rfc6125#section-6.4.3 1. The client SHOULD
by coenhyde 6y ago
This is not a valid certificate. See https://tools.ietf.org/html/rfc6125#section-6.4.3 https://tools.ietf.org/html/rfc6125#section-6.4.3
1. The client SHOULD NOT attempt to match a presented identifier in which the wildcard character comprises a label other than the left-most label (e.g., do not match bar.*.example.net).
2. If the wildcard character is the only character of the left-most label in the presented identifier, the client SHOULD NOT compare against anything but the left-most label of the reference identifier (e.g., *.example.com would match foo.example.com but not bar.foo.example.com or example.com).
- thedanbob 6y agoThose are both “should not”, not “must not”. So technically this isn’t breaking the rules, though it’s obviously incredibly not recommended.
- coenhyde 6y agoyeah but i think you'll have a hard time finding a client library which will consider the certificate valid. If it does i would consider it broken.
- 411111111111111 6y agoisnt it valid according to these rules? 1. is about wildcards in the domain part while having a hostname and 2. is in effect, which is why there are so many alternative subject names. they just added 127 subject alternative names to adhere to these rules.
- coenhyde 6y agoThose 127 SAN's have wildcards which are not the left most label, which as i interpret it would be a violation of rule 1.