danb35
Hall of Famer
- Joined
- Aug 16, 2011
- Messages
- 15,504
Now tested, and confirmed. Here's a cert I just generated on my FN11 box, for anyone else who wants to check:I'll assume (based on the bugs noted above), though I haven't yet tested, that 11-U1 does actually use the commonName as a SAN as well, but there's no field allowing you to specify additional SANs.
Code:
-----BEGIN CERTIFICATE----- MIIFmDCCA4CgAwIBAgIBAjANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEL MAkGA1UECAwCR0ExDTALBgNVBAcMBGNpdHkxDDAKBgNVBAoMA29yZzEWMBQGA1UE AwwNRnJlZU5BUyAxMSBDQTEUMBIGCSqGSIb3DQEJARYFZW1haWwwHhcNMTcwNzE1 MTA1OTA1WhcNMjcwNzEzMTA1OTA1WjBxMQswCQYDVQQGEwJVUzELMAkGA1UECAwC R0ExDTALBgNVBAcMBGNpdHkxDDAKBgNVBAoMA29yZzEiMCAGA1UEAwwZZnJlZW5h czExLmZhbWlseWJyb3duLm9yZzEUMBIGCSqGSIb3DQEJARYFZW1haWwwggIiMA0G CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC5IZdze+8bipRINetmATsX192s4rAq J6qmQXQpqGci5wllkxT8wSrwIGQsJZFMFhlChspPz0WCnRIzQYyc+pSAEWJ9vNFb NtxTKvH6/7qm/Og/dh0e+Uhg3wFbOJ4aBy21y9dk5Aob56bO2LmTfZ3omMUxoVR+ pk6M6T62i79TD7M7QM2ePNieW0PzMHp1bRXOViZIkhsCLiif0IeISDr7TJDue6Y4 ZBE7k30iw00gRqxC7cYbDiK1ktTGARpg7/ioa43bk4xTntsKW1MZl5c/qNXwf2Wq 3j+72GU+qzMDMGsJwqSvcu/zeJTCmoXlCoHNrgSS+2cljR9Z5JKQ5A4C0K2L33Te sEbwC9fflPZrKyl4L5L+FIui9B9zHLmF5xue4rj/NHsu2jUt9o3xzzyeLFS42jiX Lc614G+YZ+WAUHVQYsvBm6mGcVSK8dAgfsqlnYm7dtbfrA6vnVxMElZnuqW6JBpP eNJYEEBeRz99hyGLTM7oSe6Cf0lxNUDbUP3PnE2AuB6AP37MXDVNeUfqOAZ5fHq5 luuzCh39hibLNKP3QP2h6Db6OBFiOoD8/+nrnUnvgQIutKQ+UFHo3CnDGhYvLZ71 11t9IhbRdTSTqT++0X2bnWbB2YhVCNMRIMGr59cRfz2Yl8WunGoLFDgDP6NwTLCx 1s2JfJme1hQyZQIDAQABo0cwRTAkBgNVHREEHTAbghlmcmVlbmFzMTEuZmFtaWx5 YnJvd24ub3JnMB0GA1UdDgQWBBTexOHWVCPLoQLkTUtJmPmNV6olCjANBgkqhkiG 9w0BAQsFAAOCAgEAkrW9Mr72CdB+thnr0fnPPop/Lrp8R+6Z71v7mglOWUuE5SO3 UL4zznXmCMvm/87ge2GFprHecXLLS1qzNQ2SFqKy9uBtUw+63tSlzZD4e+abGTrE 2U037Gfsa0EM177VPhtvqtVS5ZtUDvSS6cuvlppkr7iC0LLAQ/2zAEmraM2hdAMb Bl2NpFQSRTcpDA/RXP3hCkqE9xDI+/EzeQRuH/47gV0+jm7jAKhHPs00NBBzBu8r 4NgI/Iya86xga6j2flrwVk2qQVlVBuC5Lf+nU2oa9PUMjltZ6/eSGN+Mg8r+LIQn F4zoUSVVklwNFmxBLA++BnPGuvULVfmUyC7rTOyfnIUF5FO2gt0M7bc5qJLGU8hN 2OGs4noZRazLVMLVegdf1sNjiAvAg1nD9419D5noidsGQ/fL7U2kwWgulvcWSecU bA3fIT295sWeoJafqdkCls9AVz8qXL5XYUYANAtPQTl5vcAF8rDt4502lzjDYpXf lA0y4jXDKTlnGAvcx/af9ZPeP3t69cSJlUH3nk/FIkauBTY3JD4fDc0dqIbsVxAA G0TCOjS6Vj5F8Nl55+OjgNkm9IgZ/jpCo1EQULvV1DegP7JtoqXLURZB3AJoWG5k WKhw49e2KOcBp4shtO3zxT8mNq8IHVKJDZfobZcJxCGeEwnXkBCA44ONVJk= -----END CERTIFICATE-----
It does have a SAN, but the SAN is just set to equal the CN and can't be changed through the FreeNAS web GUI. This would fix OP's problem, but wouldn't address any other possible uses of the SAN field.