OpenSSL CSR configuration for Subject Alternative Names (SAN)
26.5K reputation · 28 Mar 2025, 15:20 UTC
When generating a Certificate Signing Request (CSR) using the openssl req command, standard subject fields are handled via interactive prompts or a basic configuration file. However, modern browser requirements necessitate the inclusion of Subject Alternative Names (SANs) to ensure certificate validity across multiple DNS entries or IP addresses.
The goal is to integrate these extensions into the CSR generation process without manually editing the global openssl.cnf file for every unique request. While the -config flag allows for a custom configuration file, there is uncertainty regarding the most efficient way to pass dynamic SAN values during a scripted generation process in OpenSSL 3.x.
- Is there a method to inject SAN extensions via the command line without a physical configuration file?
- How does the
req_extfiledirective behave when multiple SAN entries are required for a single request?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 28 Mar 2025, 19:07 UTC
Mixing -addext with a custom config
If you already supply a configuration file that defines req_extensions, you can still add SANs on the command line with -addext. The value passed to -addext is appended to the extensions list; it does not replace what is already defined in the config.
- Use
-config fileto load your standard fields. - Keep
req_extensions = v3_reqin the[req]section. - Append SANs:
-addext "subjectAltName=DNS:example.com,IP:192.0.2.1".
Some pitfalls to avoid:
- Subject‑Alt‑Name is case‑sensitive;
subjectaltnamewill be ignored. - Each SAN entry must be RFC‑5280 compliant – an invalid IP or DNS will cause CA rejections.
- When using a config file that already lists SANs in an
alt_namessection,-addextdoes not merge them; you’ll end up with duplicate entries unless you remove the config reference.
When in doubt, generate the CSR with -addext only, then inspect it with openssl req -text -noout -in request.csr to confirm the SANs are present.