

15:09, EEST

March 16, 2017

Hi,
I have a question about the subjectAltName (applicationUri) for the Client Certificate
Is it needed or can it be omitted.
I remeber a long time ago, I’ve create an Client Certificate without an application uri and I could still connect to a (Demo) Server using the cert without application uri.
So would it be valid to just omit it, or does it maybe also depend on the server if it would accept a client certificate without an application uri?
Thanks!
16:04, EEST

Moderators
February 11, 2020

Hello,
According to the OPC UA Specification (https://reference.opcfoundatio…..docs/6.2.2), Application Instance Certificates shall have subjectAltName and contain the ApplicationUri as URL. For Server applications, DNS Name or IP Address should also be specified.
Thus, some OPC UA applications might accept certificates without subjectAltName, but the Specification states that they are required.
1 Guest(s)
