OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Internal certificates and Subject Alternative Names problem still exists?
« previous next »
  • Print
Pages: [1]

Author Topic: Internal certificates and Subject Alternative Names problem still exists?  (Read 2457 times)

opnsense_user12123

  • Guest
Internal certificates and Subject Alternative Names problem still exists?
« on: December 19, 2017, 07:07:38 am »
Could it be, that this Problem using alternative names still exists ?
I tried this Feature with no luck!
Should be solved - really ?

original posting:
https://forum.opnsense.org/index.php?topic=1160.msg3172#msg3172

Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13988
  • Karma: 1211
    • View Profile
Re: Internal certificates and Subject Alternative Names problem still exists?
« Reply #1 on: December 19, 2017, 07:47:15 am »
If you ask this way I'm inclined to say yes... There was, however, a bug in 17.7.9 that briefly prevented SAN due to an incompatibility with PHP 7.1 that was subsequently fixed.

So... what version are you on, what issue are you seeing? :)


Cheers,
Franco
Logged

opnsense_user12123

  • Guest
Re: Internal certificates and Subject Alternative Names problem still exists?
« Reply #2 on: December 19, 2017, 10:56:43 am »
The latest version avaible. 17.7.10
« Last Edit: December 19, 2017, 03:29:54 pm by opnsense_user12123 »
Logged

opnsense_user12123

  • Guest
Re: Internal certificates and Subject Alternative Names problem still exists?
« Reply #3 on: December 19, 2017, 10:59:20 am »
The problem is that alternative names will not be accepted. Of course you can create the certificate without any problem and export it But then , after importing the certificate On the server the web browser does not accept any of the values I had entered before for the alternative names.
Ip, Uri, DNS.its all the same problem. So I can’t browse the server with any value.

It’s very difficult to describe and my English is not so well but there is a real problem with the alternative names for sure.
« Last Edit: December 19, 2017, 11:26:13 am by opnsense_user12123 »
Logged

opnsense_user12123

  • Guest
Re: Internal certificates and Subject Alternative Names problem still exists?
« Reply #4 on: December 22, 2017, 10:02:43 pm »
i got the solution on this!

i had to enable "Log SNI information only".

what does this setting exactly do ?
Is it wrong to enable this feature ?
Does it have any disadvantages ?
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Internal certificates and Subject Alternative Names problem still exists?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2