%% You should probably cite draft-ietf-uta-rfc6125bis instead of this I-D. @techreport{ietf-uta-use-san-00, number = {draft-ietf-uta-use-san-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-uta-use-san/00/}, author = {Rich Salz}, title = {{Update to Verifying TLS Server Identities with X.509 Certificates}}, pagetotal = 5, year = 2021, month = apr, day = 1, abstract = {In the decade since {[}RFC6125{]} was published, the subjectAlternativeName extension (SAN), as defined in {[}RFC5280{]} has become ubiquitous. This document updates {[}RFC6125{]} to specify that the fall-back techniques of using the commonName attribute to identify the service must not be used. This document also places some limitations on the use of wildcards in SAN fields. The original context of {[}RFC6125{]} using X.509 certificates for server identity with Transport Layer Security (TLS), is not changed.}, }