Hi,

I have a clarifications related to $subject. When we create the keystore we
can give the SAN as below.

keytool -genkey -alias wso2carbon -keyalg RSA -keystore wso2carbon.jks
-keysize 2048 -ext SAN=dns:xyz.com,dns:abc.com,dns:hello.com

I have following two questions
1. AFAIK SANs is a meta data of public certificate. Is it correct ?
2. When we create the CSR do we have to give SANs again or is it remain
what we given while creating keystore?
3. Can we override and give different SANs while creating CSR ? I have seen
[1] we need to give SANs while creating CSR

I am bit confused on this. Can you give your feedback on this ?

[1]
https://support.microsoft.com/en-gb/help/931351/how-to-add-a-subject-alternative-name-to-a-secure-ldap-certificate

Thanks
Godwin
-- 
*Godwin Amila Shrimal*
Associate Technical Lead
WSO2 Inc.; http://wso2.com
lean.enterprise.middleware

mobile: *+94772264165*
linkedin: *https://www.linkedin.com/in/godwin-amila-2ba26844/
<https://www.linkedin.com/in/godwin-amila-2ba26844/>*
twitter: https://twitter.com/godwinamila
<http://wso2.com/signature>
_______________________________________________
Dev mailing list
Dev@wso2.org
http://wso2.org/cgi-bin/mailman/listinfo/dev

Reply via email to