# Problem with CSR for only one DNS name

**URL:** <https://community.letsencrypt.org/t/problem-with-csr-for-only-one-dns-name/19152>\
**Category:** Client dev\
**Created:** [August 22, 2016, 9:27am UTC](https://community.letsencrypt.org/t/problem-with-csr-for-only-one-dns-name/19152 "2016-08-22T09:27:24Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 9, 2016, 6:10pm UTC](https://community.letsencrypt.org/t/problem-with-csr-for-only-one-dns-name/19152/11 "2016-09-09T18:10:07Z")

</div>

The “Requested Extensions” `X509v3 Basic Constraints` and `X509v3 Key Usage` are not used. (Actually, only the CN and SAN fields are used.) So you might want to try to minimise the extras in the CSR.

Also, try to explicitely set the `Version` field to something else than “0” (default for OpenSSL \<1.0.2). [Version fields of zero generate an error on staging server (and live from January 2017). (See “Rejection of malformed CSRs”)](https://community.letsencrypt.org/t/upcoming-api-changes/17947).

I’m sure one of those (probably the latter) will fix the problem.

---

_[View the full topic](https://community.letsencrypt.org/t/problem-with-csr-for-only-one-dns-name/19152)._
