• [^] # Re: Nom de domaine intranet?

    Posté par . En réponse au journal Letsencrypt désactive l'authentification tls-sni. Évalué à 5.

    Du coup c'est impossible non?

    C’est effectivement impossible avec Let’s Encrypt, et théoriquement avec n’importe quelle CA puisque cette pratique est désormais officiellement interdite par les consignes du CA/Browser Forum (§7.1.4.2.1) :

    [....] the CA SHALL NOT issue a certificate with an Expiry Date later than 1 November 2015 with a subjectAlternativeName extension or Subject commonName field containing a Reserved IP Address or Internal Name [...]

    (Internal Name s’entendant d’un nom « that cannot be verified as globally unique within the public DNS at the time of certificate issuance because it does not end with a Top Level Domain registered in IANA’s Root Zone Database. »)

    Après, si tu veux réellement un tel certificat, tu trouveras bien une CA qui pourras t’en fournir un...