X.509证书中的专有名称长度约束

编程入门 行业动态 更新时间:2024-10-24 12:22:22
本文介绍了X.509证书中的专有名称长度约束的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧! 问题描述

在 DN (对于OID" 2.5.4.3的ASN.1注释中定义),最大限制为64个字符.如果我们要使用超过64个字符的通用名称,是否可以解决?

In the common name field of the DN of a X509 certificate, as defined in ASN.1 notation for OID "2.5.4.3", the limit is up to 64 characters. Is there any turnaround if we want to have a common name of more than 64 characters?

推荐答案

即使您可以哄骗证书生成代码以拥有更长的CN,也需要更改 clients 大多数您无法控制.客户很可能会拒绝CN太长的证书,然后您根本没有证书.

Even if you could cajole your certificate generation code to have a longer CN, it's also the clients that will need to change, of which most you have no control over. Clients could well reject a certificate with a too-long CN and then you'll have no certificate at all.

如评论中所述,您可以(并且应该)将该域名和其他域名放入使用者备用名称"扩展名中,并将CN留空.不是整个主题",而是它的CN部分.

As mentioned in the comments, you can (and should) put that and other domain names into the Subject Alternate Name extension and leave the CN empty. Not the whole "Subject", but just the CN part of it.

更多推荐

X.509证书中的专有名称长度约束

本文发布于:2023-10-23 01:58:28,感谢您对本站的认可!
本文链接:https://www.elefans.com/category/jswz/34/1519403.html
版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。
本文标签:长度   证书   名称

发布评论

评论列表 (有 0 条评论)
草根站长

>www.elefans.com

编程频道|电子爱好者 - 技术资讯及电子产品介绍!