|
|
|
|
|
by xg15
134 days ago
|
|
> How do you verify the common name/subject alt name actually matches when using a client cert. This seems exactly like a reason to use client certs with public CAs. You (as in, the server) cannot verify this at all, but a public CA could. |
|
If it's for auth, issue it yourself and don't rely on a third-party like a public CA.