Using the Subject Alternative Name Field When Generating a Certificate
book
Article ID: 290824
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
How to use the Subject Alternative Name (SAN) field when generating a new Communication Certificate to be used in the Console.
Environment
- App Control Console: All Supported Versions
Resolution
A Subject Alternative Name is required when:
- The Server Address was changed and Agents have not been updated via the setserver command.
- The Common Name on the Communication Certificate and the Server Address are not identical.
If a Subject Alternative Name (SAN) is required, it must:
Additional Information
- Failure to properly format the Server Certificate could cause communication failures between the Agent and the Server, or other errors.
- The SAN can also contain an IP Address, or a wildcard:
DNS=appcontrol.domain.com,DNS=*.domain.com,IP=10.0.8.123
- If a Wildcard is used in the Common Name, the current Server Address (System Configuration > General) must be included in the SAN:
Common Name: *.domain.com
Subject Alternative Name: DNS=appcontrol.domain.com,DNS=*.domain.com
- RFC 2818 states that the Common Name in the Subject field of the certificate must be included in the Subject Alternative Name.
Feedback
thumb_up
Yes
thumb_down
No