Common Name Only #43
Unanswered
karabelnikov
asked this question in
Q&A
Replies: 1 comment
-
Shura, it's been a while, but my recollection is that those values add additional "randomness" to the creation of certificates and keys. Without them, I believe the encryption would be slightly easier to crack. If PiVPN doesn't use them anymore, or maybe more importantly EasyRSA, then we could probably eliminate them. Like so many things, I'd need to look at the code to be sure getting rid of them won't cause other issues. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
@bnhf
Scott, I suggest moving the project to use set_var EASYRSA_DN=cn_only instead of set_var EASYRSA_DN=org
I consider it redundant. Since information other than CN is essentially static, we no longer display it in our certificate table.
And the OpenVPN installation scripts, in particular, PiVPN uses CN_only.
Beta Was this translation helpful? Give feedback.
All reactions