SSL Certificate with SubjectAlternativeName (SAN)

If you want to create an SSL certificate for multiple subdomains, you could either use a wildcard certificate like * or you could use an SSL certificate with SubjectAlternativeName (SAN).

For example, if you create an SSL certificate with SubjectAlternativeName (SAN) like this:


In my understanding it was one main name ( and two aliases (,

But when I’ve accessed with my browser, the certificate (canonical name) was marked as invalid:

Certificate error
There are issues with the site's certificate chain


As mentioned in the RFC6125 (released in 2011) the certificate validation must check for SAN (SubjectAlternativeName) first. If SAN exists, then the CN (Common Name) will be ignored:


If a subjectAltName extension of type dNSName is present, that MUST be used as the identity. Otherwise, the (most specific) Common Name field in the Subject field of the certificate MUST be used. Although the use of the Common Name is existing practice, it is deprecated and Certification Authorities are encouraged to use the dNSName instead.


So keep in mind, if you have an SSL certificate which uses SAN (SubjectAlternativeName) you must provide all aliases for your domain as SubjectAlternativeName, because CN (Common Name) will be ignored!

You can check your certificate content with the following openssl command:

$ openssl x509 -in -text -noout
 X509v3 Subject Alternative Name:,,

Just check if all of your desired aliases/subdomains are present in the X509v3 Subject Alternative Name section.

Note: You can easily generate your own Let’sEncrypt SSL certificate with SubjectAlternativeName (SAN) via certbot


  • Gaurav

    Hi Roger, Apart from DNS name SAN extension allows to provide IP address and e-mail addresses. In what scenarios using IP address and e-mail addresses would be useful. I understood the use case of DNS in SAN, but do not have any idea about e-mail and IP address.

  • halki diabetes remedy

    I think it is very complimentary to navigation and helps out a lot!

  • geometry dash

    To get a good blog I think you tried a lot. And I think this is a very interesting blog, it attracts me by the content and creative design.

  • word finder

    Rich information, that’s really good, I’m looking for it, thanks for sharing.

  • pergola renovations

    This Blog Is All About The Facts Of Excellent Information Which You Provide. I Thankful To You For Sharing Amazing And Unique Content On Your Web Blog.

  • Website

    I love this weblog, wonderful content material and I am going to bookmark this website.

  • https //

    Mind boggling information. Blessed me I went over your site by some happenstance (stumbleupon). I’ve book-checked it for later!