boulder icon indicating copy to clipboard operation
boulder copied to clipboard

Allow CSRs whose CN is longer than acceptable

Open aarongable opened this issue 1 year ago • 0 comments

Today, if someone submits a CSR with a CN, we respect that CN and carry it over to the issued certificate. (If their CSR doesn't have a CN, we promote one of their SANs, unless none of the SANs fit.) But if their CSR's CN doesn't fit in a certificate's CN, then we refuse to issue.

Instead, we should just ignore that suggested CN and issue the cert without a CN, the same as if all the SANs had been too long.

aarongable avatar Jul 22 '24 21:07 aarongable