IP SAN error: "CSR contains IP address in Common Name"

The most important message IMO comes from the comment added in the code:

We want to get rid of CNs entirely anyway, and IP addresses are a new feature, so don't let clients get in the habit of including them in the CN.

While technically allowed, LE simply doesn't want to include it due to its deprecated status for this new feature that nobody has gotten change to get used to yet.

5 Likes