Support for commonName matching in Certificates (removed)

RFC 2818 describes two methods to match a domain name against a certificate - using the available names within the subjectAlternativeName extension, or, in the absence of a SAN extension, falling back to the commonName. The fallback to the commonName was deprecated in RFC 2818 (published in 2000), but support still remains in a number of TLS clients, often incorrectly.

Comments

Firefox has removed support in Firefox 48 (meaning "Supports removal")

Documentation

Specification

Established standard

Status in Chromium

Internals>Network>Certificate


Removed (launch bug) in:

  • Chrome for desktop release 58
  • Chrome for Android release 58
  • Chrome for iOS release 58
  • Android WebView release 58
  • Opera release 45
  • Opera for Android release 45

Consensus & Standardization

  • Opposed
  • No public signals
  • No public signals
  • No signals

Owner

Last updated on 2017-06-14