查看证书时是否应该能够看到 subjectAltName 选项?
我已请求带有多个 subjectAltNames 的证书(适用于 IIS 7 上的 SSL)。我读到有些人可能不喜欢这样做,因为公众能够看到不同网站之间的链接。 (这并不重要,因为证书供内部使用)。但这表明我在查看证书时应该能够看到 subjectAltNames。我不能。
我应该能够看到他们吗?如果可以,在哪里?
I've requested an certificate (for SSL on IIS 7) with several subjectAltNames. I'd read that some people might not like to do this because of the public being able to see links between different sites. (This doesn't matter as the certificate is for internal use). But this suggests that I should be able to see the subjectAltNames when I view the certificate. I can't.
Should I be able to see them, and if so, where?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
是的 - 但这取决于您使用的证书查看器。
主题替代名称是证书的扩展。它仍然作为证书签名的一部分进行签名,但可能无法通过所有看到证书的事物来查看。它具体出现在哪里,在某种程度上取决于你如何看待它。它位于证书扩展中。通常它被限定为“主题备用名称”或“SubjectAltName”。
我刚刚在 XP 上测试了 IE 7.0,它可以显示主题 Alt 名称。它显示为详细项目之一。
此外,该网站将:
http://www.redkestrel.co.uk/cgi/解码Cert.pl
因为我之前已经从中获得了主题替代名称。它们出现在扩展部分。
如果它没有显示在那里,则证书可能是在没有它的情况下创建的,这意味着您需要返回证书颁发机构的所有者并重新创建名称。
另一个警告 - 并非所有产品都会处理主题替代名称。您需要分别测试每一项。我听说过许多产品无法识别或解析它的情况,然后抛出错误,因为SubjectDN 没有映射到主题替代名称。
Yes -- but it depends on the certificate viewer that you are using.
Subject Alt Name is an extension to the certificate. It is still signed as part of the certificate signature, but it may not be viewable through all the things that see certificates. Where it specifically shows up is somewhat a factor of how you are looking at it. It is in the certificate extensions. Usually it's qualied as "Subject Alternative Name" or "SubjectAltName".
I just tested IE 7.0 on XP and it can show the Subject Alt Name. It shows up as one of the detail items.
Also, this site will:
http://www.redkestrel.co.uk/cgi/decodeCert.pl
As I've gotten Subject Alt Names out of it before. They show up in the extension section.
If it's not showing up there, the certificate may have been made without it, which means you will need to go back to the owner of the Certificate Authority and get the name recreated.
Another caveat - not all products will handle subject alt name. You'll need to test each one separately. I've heard of a number of cases of products not recognizing it or parsing it, and then throwing errors because the SubjectDN does not map to the subject alt name.