Details
-
Improvement
-
Resolution: Unresolved
-
Major - P3
-
None
-
3.0.0
-
Server Security
Description
Subject Alternative Names that are IP addresses have to be specifically identified as such. But server.pem and several others in jstests/lib have this:
X509v3 Subject Alternative Name:
|
DNS:localhost, DNS:127.0.0.1
|
whereas it should be:
X509v3 Subject Alternative Name:
|
DNS:localhost, IP:127.0.0.1
|
Correctly written clients will fail to connect on 127.0.0.1 to a server presenting this certificate.
Attachments
Issue Links
- is depended on by
-
JAVA-1687 Enable SSL host name verification for automated SSL tests
-
- Closed
-