Subject alternative names (SAN)
SAN allows you to define the subject alternative name extensions in the certificate.
You can use the JSON template for each type of SAN entry to specify inclusion rules, define automatic inclusion based on the common name, and determining the data sources—including Certificate Signing Requests (CSR), predefined values, or user input. This configuration offers the flexibility needed to meet specific security standards and manage SAN fields effectively during certificate issuance.
The provided JSON examples details how to configure Subject Alternative Names (SAN) for a certificate template, covering various data types such as DNS names, IP addresses, and email addresses.
JSON structure examples
"extensions": {
"san": {
"critical": false,
"dns_name": {
"include": "yes",
"auto_include_cn": "no",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
},
"ip_address": {
"include": "yes",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
},
"user_principal_name": {
"include": "yes",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
},
"email": {
"include": "yes",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
},
"uri": {
"include": "yes",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
},
"registered_id": {
"include": "yes",
"allowed_source": [
"csr",
"fixed_value",
"user_supplied"
]
}
}
}"extensions": {
"san": {
"critical": false,
"other_name": {
"required_types": [
"hardware_module_name"
],
"hardware_module_name": {
"type": "1.2.240.458.10003.3.12",
"serial_num": "aabbcc001122"
},
}
}
}"extensions": {
"san": {
"critical": false,
"other_name": {
"required_raw_types": [
"1.2.3.456.7890.1",
"1.2.3.456.7890.2"
],
"optional_raw_types": [
"1.2.3.456.7890.3",
"1.2.3.456.7890.4"
]
}
}
}Parameters
Name | Type | Required/optional | Possible values |
|---|---|---|---|
| Object | Optional | - |
| Boolean | Optional | Specifies whether the SAN extension is marked as critical. Supported values include:
|
| Object | Optional | - |
| String | Optional | Specifies whether DNS names are included in the SAN extension. Supported values include:
|
| String | Optional | Specifies whether the Common Name (CN) is automatically added as a DNS name. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for DNS name values. Supported values include:
|
| Object | Optional | - |
| String | Specifies whether IP addresses are included in the SAN extension. Supported values include:
| |
| Array of strings |
| Specifies the allowed sources for IP address values. Supported values include:
|
| Object | Optional | - |
| String | Optional | Specifies whether UPN values are included in the SAN extension. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for UPN values. Supported values include:
|
| Object | Optional | - |
| String | Optional | Specifies whether email addresses are included in the SAN extension. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for email address values. Supported values include:
|
| Object | Optional | - |
| String | Optional | Specifies whether URI values are included in the SAN extension. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for URI values. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for URI values. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for URI values. Supported values include:
|
| Object | Optional | - |
| String | Optinal | Specifies whether Registered ID values are included in the SAN extension. Supported values include:
|
| Array of strings | Required | Specifies the allowed sources for Registered ID values. Supported values include:
|
| Object | Optional | - |
| Array of strings | Required (for raw | Specifies the OIDs that must be present in the raw 참고 Use this property only when defining a raw |
| Array of strings | Optional | Specifies the OIDs that must be present in the raw 참고 Use this property only when defining a raw |
| Array of strings | Required (for hardware modules) | Specifies the OIDs that must be present in the 참고Use this property only when defining a hardware module name |
| Object | Optional | - |
| String | Required | Specifies the OID that identifies the hardware module type |
| String | Optional | Specifies the hardware module serial number as a hexadecimal-encoded binary value |