New issue
Advanced search Search tips

Issue 716465 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 700595
Owner: ----
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

When a CN Exists, a SAN should not be required as well

Reported by mrsmit4@gmail.com, Apr 28 2017

Issue description

Chrome Version       : 58.0.3029.81
URLs (if applicable) : N/A (Internal Site)
Other browsers tested: OK - IE 11
Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
     Safari:
    Firefox:
         IE: 11 - OK

What steps will reproduce the problem?
(1) Login to any secured site using Chrome 58 that does not include Subject Alternative Names
(2)
(3)

What is the expected result?
If a site has a correct CN for the site, it should resolve and be considered secure.  

What happens instead?
I got an "Insecure" error with stating that we have a missing Subject Alternative Name.  Several tools, like Portecle, don't even give you the ability to add a SAN.

Please provide any additional information below. Attach a screenshot if
possible.

 

Comment 1 by mmenke@chromium.org, Apr 28 2017

Mergedinto: 700595
Status: Duplicate (was: Unconfirmed)
The examples of the insecurity related to Common Name support can be found at https://nameconstraints.bettertls.com/

Also see RFC 2818, published 17 years ago.

Sign in to add a comment