> On 18 Nov 2020, at 11:45, Marc Sauton wrote:
>
> and add a
> default:DNCompscn
> to match the DN components
> ?
>
That changes the search basedn, not the matched dn or attribute content. I
think they want to put the cert subject in nsCertSubjectDN and search all BE's,
especially
and add a
default:DNCompscn
to match the DN components
?
On Tue, Nov 17, 2020 at 5:35 PM William Brown wrote:
>
> >
> > Something missing from the documentation is the DN format expected by
> the nsCertSubjectDN attribute.
> >
> > Is the format CN=X,serialNumber=Y as reported by openssl
>
> Something missing from the documentation is the DN format expected by the
> nsCertSubjectDN attribute.
>
> Is the format CN=X,serialNumber=Y as reported by openssl x509, or is it
> serialNumber=Y,CN=X as reported by the log message above?
I seem to recall a few years back, some changes