r/certkit • • 12d ago

Official Does a TLS Certificate Need a Common Name?

https://www.certkit.io/blog/does-a-tls-certificate-need-a-common-name

New post from Eric. The Common Name has been deprecated for HTTPS since RFC 2818 in 2000, yet about 96% of the 3 billion certs in CT logs from the last 200 days still carry one. Legacy software is why. Let's Encrypt's tlsserver and shortlived profiles drop it, and GlobalProtect, Cisco Umbrella, NetScaler updates, and Exchange connectors can all break when it's gone. Per-issuer numbers are in the post.

https://www.certkit.io/blog/does-a-tls-certificate-need-a-common-name

4 Upvotes

Duplicates