Hi @bbockelm, maybe I misunderstood, but I commented on the suggested implementation of RFC2818, which doesn't require the use of SANs, but allows using CN=hostname instead. If that check matches, there is no need to go steps 2 and 3. I fully agree with your 'tweak' -- You are receiving this because you commented. Reply to this email directly or view it on GitHub: https://github.com/xrootd/xrootd/issues/841#issuecomment-433074410 ######################################################################## Use REPLY-ALL to reply to list To unsubscribe from the XROOTD-DEV list, click the following link: https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1