跳转到主内容

使用者备用名称(SAN)通配符替换了多少级别?

Views:
57
Visibility:
Public
Votes:
0
Category:
storagegrid
Specialty:
sgrid
Last Updated:

适用于

  • StorageGRID
  • S3 虚拟托管风格请求

问题解答

单个关卡。

通配符 TLS/SSL 证书使用一个证书来保护单个域和所有相关子域,从而简化子域管理并降低成本。

通过使用星号符号 (*) 作为占位符 (*.example.com),通配符证书将自动保护同一级别下的任何子域。
 
如果通配符 Subject Alternative Name (SAN) 为 *.company.com:
 
可以使用:support.company.com 或 mybucket.company.com
 
不能使用:mybucket.support.company.com
 
命令:curl -v -X OPTIONS https://mybucket.support.company.com 将导致错误,例如:
 
SSL: no alternative certificate subject name matches target host name 'mybucket.support.company.com'
 
 
注意:当使用虚拟托管样式的 SSL 连接失败时,像 Cyberduck 这样的客户端将自动从  虚拟托管样式切换到路径样式。
NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.