QuestionQ32

Security Engineering

An administrator needs to craft a single certificate-signing request for a web-server certificate. The server should be able to use the following identities to mutually authenticate other resources over TLS:

• www.int.comptia.org

• webserver01 .int.comptia.org

• 10.5.100.10

Which of the following certificate fields must be set properly to support this objective?

Explanation

The Subject Alternative Name (SAN) extension is what allows a single certificate to bind multiple identities — additional DNS names and an IP address — so the server can be validated under any of those names or addresses during mutual TLS authentication. Extended key usage governs what the certificate can be used for, not which identities it covers.

Community Discussion

No comments yet. Be the first to start the discussion!