• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Feature-Request: "SubjectAlternativeNames" in CSR (X509 V3)

cyberjunk

New Pleskian
Where:
Plesk UI -> "Add SSL Certificate"

What:
It is possible to provide "alternative" names in certificates and their CSRs (additional to the main FQDN which is read from the "Domain name" in the plesk UI).

It's NOT supported by all CA/any cheap certificate.

It's well described here:
http://apetec.com/support/GenerateSAN-CSR.htm

I would like the UI being improved to allow entering subect alternative values which then will be included in the CSR or selfsigned certificate.

Benefits:
(a) This could be useful for professional users with expansive wildcard certificates (*.company.com). It's common to integrate the rootdomain (company.com) as an alternative name in such. Otherwise using a *.company.com certificate on company.com usually gives issues.
(b) This can improve the quality of self-signed certificates. Of course they will still warn the users about being self-signed, but the additional warning about being not correct for the destination they entered (e.g. they opened company.com instead of www.company.com) would disappear.

PS: cPanel seems to support it ;-)
 
Last edited:
Back
Top