cURL / Mailing Lists / curl-library / Single Mail

curl-library

Re: subjectAltName does not match - Wrong test?!

From: Sven Anders <anders_at_anduras.de>
Date: Tue, 15 Sep 2009 11:37:28 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Peter Sylvester schrieb:
> Sven Anders wrote:
>> Hello!
>>
>> After upgrading from 7.19.4 to 7.19.6 I experiencing the following
>> problem:
>>
>> I'm getting the following error message:
>> "subjectAltName does not match <URL>"
>>
>> In detail I have the following entries:
>>
>> Issuer: CN=www.anduras.de, C=DE, L=Passau, ST=Bavaria, O=ANDURAS
>> AG, OU=Security/emailAddress=xxx_at_anduras.de
>> Subject: C=DE, L=Passau, ST=Bavaria, O=ANDURAS
>> AG/emailAddress=yyy_at_anduras.de, C=Germany
>> X509v3 extensions:
>> X509v3 Subject Alternative Name:
>> email:yyy_at_anduras.de
> can you send your certificate, the above extract looks somewhat
> strange.
>
Ok, here is the complete cert for reference:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 6 (0x6)
        Signature Algorithm: md5WithRSAEncryption
        Issuer: CN=www.anduras.de, C=DE, L=Passau, ST=Bavaria,
O=ANDURAS AG, OU=Security/emailAddress=xxx_at_anduras.de
        Validity
            Not Before: Jan 1 00:00:00 2005 GMT
            Not After : Dec 31 23:59:59 2009 GMT
        Subject: CN=www2.anduras.de, C=DE, L=Passau, ST=Bavaria,
O=ANDURAS AG, OU=Security/emailAddress=xxx_at_anduras.de, C=Germany
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:......
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Key Identifier:
             
E0:AB:B8:8E:8C:8F:27:C3:17:27:1E:AD:CE:59:CF:70:88:3B:BB:F5
            X509v3 Authority Key Identifier:
             
keyid:4A:41:D8:CD:17:C0:3B:64:2F:C7:5A:85:85:2D:4B:3A:67:F2:FC:33
             
DirName:/CN=www.anduras.de/C=DE/L=Passau/ST=Bavaria/O=ANDURAS
AG/OU=Security/emailAddress=xxx_at_anduras.de
                serial:01

            X509v3 Key Usage:
                Digital Signature, Non Repudiation, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Server Authentication
            X509v3 Subject Alternative Name:
                email:xxx_at_anduras.de
            Netscape Cert Type:
                SSL Server
            Netscape Comment:
                xca certificate
    Signature Algorithm: md5WithRSAEncryption
        ae:...

Regards
 Sven

- --
 Sven Anders <anders_at_anduras.de> () Ascii Ribbon Campaign
                                                 /\ Support plain text
e-mail
 ANDURAS service solutions AG
 Innstraße 71 - 94036 Passau - Germany
 Web: www.anduras.de - Tel: +49 (0)851-4 90 50-0 - Fax: +49 (0)851-4
90 50-55

Rechtsform: Aktiengesellschaft - Sitz: Passau - Amtsgericht Passau HRB
6032
Mitglieder des Vorstands: Sven Anders, Marcus Junker
Vorsitzender des Aufsichtsrats: Mark Peters
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkqvYFgACgkQ5lKZ7Feg4EdgSwCdFaoRUl3CfXJuFzg0mIplI+jp
exEAn04Fl/A1gqftB/IRtI8Z8TXedZBR
=U+KN
-----END PGP SIGNATURE-----
Received on 2009-09-15