SQL Server and Client-Side DNS: Certificate Subject Name Validation
28K reputation · 05 Feb 2023, 18:13 UTC
TLS Handshake and Hostname Resolution
When establishing a secure connection to Microsoft SQL Server using Encrypt=True and TrustServerCertificate=False, the client must validate that the server's identity matches the certificate provided during the TLS handshake.
The validation process typically relies on the hostname specified in the connection string. If the client uses a DNS alias (CNAME) or a load balancer virtual IP to reach the server, the underlying Windows DNS resolution may return a name that differs from the Common Name (CN) or Subject Alternative Name (SAN) embedded in the server's certificate.
Integration Constraints
- The client must trust the Root CA that signed the server certificate.
- The connection string hostname must align with the certificate's identity to avoid validation failures.
Given these requirements, how does SQL Server handle validation when the DNS-resolved name differs from the connection string's target? What are the specific requirements for the Subject Alternative Name (SAN) field to support multiple DNS aliases in a high-availability environment?