Hi all, I think Xrootd should imitate Globus in this matter: by default, the client should compare the name it used to contact the service with the names in the SAN and fall back on the subject DN as needed. Better yet, for the time being it could still fall back on the DNS if no match was found yet. Just as Globus did, at some point the latter fall-back is no longer tried by default, but still available through a run-time configuration option. In the end, possibly after a few years, that route is removed altogether. -- You are receiving this because you commented. Reply to this email directly or view it on GitHub: https://github.com/xrootd/xrootd/issues/841#issuecomment-431070343 ######################################################################## Use REPLY-ALL to reply to list To unsubscribe from the XROOTD-DEV list, click the following link: https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1