ACTION-517: Check EV expectations for subjectAltName

EV guidelines <URL:  
http://www.cabforum.org/EV_Certificate_Guidelines_V11.pdf > section D.6  
point a.2 says

-------------
Domain name

Certificate Field: subject:commonName (OID 2.5.4.3) or  
SubjectAlternativeName:dNSName

Required/Optional: Required

Contents: This field MUST contain one or more host domain name(s) owned
or controlled by the Subject and to be associated with Subject’s server.  
Such
server MAY be owned and operated by the Subject or another entity (e.g., a
hosting service). Wildcard certificates are not allowed for EV  
certificates.
-----------------

There is no statement saying how clients should prioritize the  
information, but that is really implied by the HTTP over TLS RFC.

-- 
Sincerely,
Yngve N. Pettersen
********************************************************************
Senior Developer       Email: yngve@opera.com
Opera Software ASA                   http://www.opera.com/
Phone:  +47 24 16 42 60              Fax:    +47 24 16 40 01
********************************************************************

Received on Wednesday, 8 October 2008 15:33:04 UTC