MikeBishop / http2-certs

Enabling client certificate authentication in HTTP/2
3 stars 2 forks source link

Matching rules for subjectAltName #8

Open MikeBishop opened 8 years ago

MikeBishop commented 8 years ago

From Andrei:

if you require support for this OID [subjectAltName] in the CERTIFICATE_REQUEST, then you have to define matching rules (see https://tools.ietf.org/html/draft-ietf-tls-tls13-12#section-6.3.3.2 for an example).

I would have thought they were already defined somewhere, but if not….

martinthomson commented 8 years ago

RFC 6125