> > [alt_names] DNS.1 = hkps.pool.sks-keyservers.net DNS.2 =
> > *.pool.sks-keyservers.net DNS.3 = pool.sks-keyservers.net DNS.4 =
> > keys.niif.hu
>
> This part is unnecessary, the SANs are added by me the input is
> discarded when generating the certificate. So you can simplify this to
Anyway the result is this:
$ openssl x509 -in hkps.pool.sks-keyservers.net.crt -noout -text
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 94 (0x5e)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=NO, ST=Oslo, O=sks-keyservers.net CA, CN=sks-keyservers.net CA
Validity
Not Before: May 16 11:26:58 2015 GMT
Not After : May 15 11:26:58 2016 GMT
Subject: C=HU, O=NIIF Institute, CN=keys.niif.hu
[...]
X509v3 Subject Alternative Name:
DNS:hkps.pool.sks-keyservers.net,
DNS:*.pool.sks-keyservers.net, DNS:pool.sks-keyservers.net, DNS:keys.niif.hu
[...]
Gabor
_______________________________________________
Sks-devel mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/sks-devel