Not sure where to note this, but one thing for implementers to bear in mind is that names returned from DNS-SD seem often to have the trailing '.' that indicates an FQDN (e.g. "mocks.testsuite.nmos.tv."), whereas certs are normally issued with CN/SANs that are DNS names without the (implied...) trailing '.' (e.g. "mocks.testsuite.nmos.tv"). Name matching needs to take this into account, although RFC 2818 does not make it clear.
Not sure where to note this, but one thing for implementers to bear in mind is that names returned from DNS-SD seem often to have the trailing '.' that indicates an FQDN (e.g. "mocks.testsuite.nmos.tv."), whereas certs are normally issued with CN/SANs that are DNS names without the (implied...) trailing '.' (e.g. "mocks.testsuite.nmos.tv"). Name matching needs to take this into account, although RFC 2818 does not make it clear.
('transferred' from https://github.com/AMWA-TV/nmos-testing/issues/207)