Validating identity message

Validating identity message

For TLS authentication with X.509 certificates, an identity from the DNS namespace MUST be checked against each subject Alt Name extension of type d NSName present in the certificate.

This section defines the identity comparison algorithm for a single APD entry.

[SIP] does not provide any guidelines on the presence of wildcards in certificates.

[PKIX], while not disallowing this explicitly, leaves the interpretation of wildcards to the individual specification.

the Responding node) or psk_identity (for the client identity, i.e. When matching DNS names against d NSName or Common Name fields, matching is case- insensitive. If no such extension is present, then the identity MUST be compared to the (most specific) Common Name in the Subject field of the certificate. Implementations MUST NOT match any form of wildcard, such as a leading "." or "*." with any other DNS label or sequence of labels. For example, "" does not match "".

Abstract Many application technologies enable secure communication between two entities by means of Internet Public Key Infrastructure Using X.509 (PKIX) certificates in the context of Transport Layer Security (TLS).