Connection between iOS 9 support and Subject Common Name or X509v3 Subject Alternative Name Critical?

The first phase will probably be omitting the CN when none of the SANs are short enough to fit in the size limit, which is a strict improvement over failing to issue certs, but is still potentially troublesome if those certs don't universally work. It definitely seems like a change that's perilous, as this thread shows.

I think it probably makes sense to have a flag / pair of flags to control whether certbot includes a CN, but that's firmly into making dangerous compatibility hazards for all but the most sophisticated users with a deep understanding of the x509 ecosystem.

4 Likes