Forum Discussion
SAN name is not working
The default, if nothing matches, in a SAN certificate, should be whatever the subject name is (versus the subject alt names).
Let's say you have a SAN cert with a subject of xyz.com and two subjectAltNames of abc.com and www.abc.com.
You've applied this single SAN cert to a single client SSL profile and applied that to your VIP.
A user reaches your site with **xyz.com** and everything is good.
A user reaches your site with **abc.com** and everything is good.
A user reaches your site with **www.abc.com** and everything is good.
A user reaches your site with **foo.example.com and** and the match fails.
This is to be expected. In an SNI configuration, the "default" option indicates that a given client SSL profile should be chosen if none of the server name strings match the client's request. If that default client SSL profile and corresponding certificate still doesn't match the client's request, then you'll have a mismatch condition.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com