{"id":3094,"date":"2023-11-07T15:09:43","date_gmt":"2023-11-07T11:09:43","guid":{"rendered":"https:\/\/extralan.ru\/?p=3094"},"modified":"2023-11-10T15:29:55","modified_gmt":"2023-11-10T11:29:55","slug":"%d0%b2%d1%8b%d0%b4%d0%b0%d1%87%d0%b0-%d1%81%d0%b5%d1%80%d1%82%d0%b8%d1%84%d0%b8%d0%ba%d0%b0%d1%82%d0%be%d0%b2-%d0%b4%d0%bb%d1%8f-apache2-%d1%81-subject-alternative-name-san","status":"publish","type":"post","link":"https:\/\/extralan.ru\/?p=3094","title":{"rendered":"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN)"},"content":{"rendered":"\n<p>\u0418\u043c\u0435\u0435\u0442\u0441\u044f \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0446\u0435\u043d\u0442\u0440 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435<strong> Windows Server Active Directory\u00a0Certificate\u00a0Services (AD CS)<\/strong>. \u0417\u0430\u0434\u0430\u0447\u0430: \u0432\u044b\u0434\u0430\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441 <strong>Apache2<\/strong> \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430\u0445 Chrome \u0438 Edge (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 <strong>SAN<\/strong> \u043e\u043f\u0446\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 0<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2. <\/strong><\/p>\n\n\n\n<p>\u041e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c\u0441\u044f \u0433\u0434\u0435 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0432 \u0445\u043e\u0434\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438, \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e: <strong>\/home\/administrator\/certs\/webserver.domain.ru<\/strong> \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c \u0432 \u0434\u0430\u043d\u043d\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 1<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2.<\/strong> <\/p>\n\n\n\n<p>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b <strong>webserver.domain.ru.cnf<\/strong> \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0433\u043e \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u043d\u0438\u044f:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; req ]\ndefault_bits            = 2048\ndistinguished_name      = req_distinguished_name\n\nstring_mask = utf8only\n\nreq_extensions = v3_req # The extensions to add to a certificate request\n\n&#91; req_distinguished_name ]\ncountryName                     = Country Name (2 letter code)\ncountryName_default             = AU\ncountryName_min                 = 2\ncountryName_max                 = 2\n\nstateOrProvinceName             = State or Province Name (full name)\nstateOrProvinceName_default     = Some-State\n\nlocalityName                    = Locality Name (eg, city)\n\n0.organizationName              = Organization Name (eg, company)\n0.organizationName_default      = Internet Widgits Pty Ltd\n\norganizationalUnitName          = Organizational Unit Name (eg, section)\n#organizationalUnitName_default =\n\ncommonName                      = Common Name (e.g. server FQDN or YOUR name)\ncommonName_max                  = 64\n\nemailAddress                    = Email Address\nemailAddress_max                = 64\n\n&#91; req_attributes ]\nchallengePassword               = A challenge password\nchallengePassword_min           = 4\nchallengePassword_max           = 20\n\nunstructuredName                = An optional company name\n\n&#91; v3_req ]\n\n# Extensions to add to a certificate request\n\nbasicConstraints = CA:FALSE\nkeyUsage = nonRepudiation, digitalSignature, keyEncipherment\nsubjectAltName = @alt_names\n\n&#91; alt_names ]\nDNS.1 = webserver.domain.ru\n<\/code><\/pre>\n\n\n\n<p>\u0417\u0434\u0435\u0441\u044c \u043e\u0441\u043e\u0431\u043e\u0435 \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u043d\u0443\u0436\u043d\u043e \u0443\u0434\u0435\u043b\u0438\u0442\u044c \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c:<\/p>\n\n\n\n<p>req_extensions = v3_req &#8212; \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043d\u0443\u0436\u043d\u0443\u044e \u0441\u0435\u043a\u0446\u0438\u044e.<\/p>\n\n\n\n<p>keyUsage = nonRepudiation, digitalSignature, keyEncipherment &#8212; \u0437\u0430\u0434\u0430\u0451\u0442 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0435 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u0434\u0430\u043d\u043d\u044b\u0445 \u043e\u043f\u0446\u0438\u0439 \u043d\u0435 \u0434\u0430\u0441\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u043d\u0430 \u0435\u0433\u043e \u043e\u0441\u043d\u043e\u0432\u0435 \u0447\u0442\u043e \u043b\u043e\u0433\u0438\u0447\u043d\u043e \u0432 \u0434\u0430\u043d\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435.<\/p>\n\n\n\n<p>subjectAltName = @alt_names \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u0441\u0435\u043a\u0446\u0438\u044e, \u0433\u0434\u0435 \u0431\u0443\u0434\u0435\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0442\u044c SAN \u0434\u043b\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430<\/p>\n\n\n\n<p>[ alt_names ] DNS.1 = webserver.domain.ru &#8212; SAN \u0437\u0430\u043f\u0438\u0441\u044c, \u043c\u043e\u0436\u043d\u043e \u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e DNS.2, DNS.3 \u0438 \u0442\u0430\u043a \u0434\u0430\u043b\u0435\u0435.<\/p>\n\n\n\n<p>webserver.domain.ru &#8212; FQDN \u0438\u043c\u044f \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u043a \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u0431\u0443\u0434\u0443\u0442 \u043e\u0431\u0440\u0430\u0449\u0430\u0442\u044c\u0441\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u044b.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 2<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2.<\/strong> <\/p>\n\n\n\n<p>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u043a\u043b\u044e\u0447 \u0438 \u0437\u0430\u043f\u0440\u043e\u0441 \u043d\u0430 \u0432\u044b\u0434\u0430\u0447\u0443 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b openssl, \u0441\u0434\u0435\u043b\u0430\u043d\u043d\u044b\u0439 \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0448\u0430\u0433\u0435.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl genrsa -out webserver.domain.ru.key 2048\n\nopenssl req -new -nodes -keyout webserver.domain.ru.key -out webserver.domain.ru.req -config webserver.domain.ru.cnf\n# \u041d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0432\u0432\u0435\u0441\u0442\u0438 \u0442\u043e\u043b\u044c\u043a\u043e: Common Name (e.g. server FQDN or YOUR name) &#91;]:webserver.domain.ru\n# \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438.\n# \u0415\u0441\u043b\u0438 \u0441\u043f\u0440\u043e\u0441\u0438\u0442 \u043f\u0430\u0440\u043e\u043b\u044c, \u0442\u043e \u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0435\u0433\u043e \u043f\u0443\u0441\u0442\u044b\u043c.<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 3<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 Certification Authority \u0441\u0435\u0440\u0432\u0435\u0440\u0430.<\/strong> <\/p>\n\n\n\n<p>\u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0432 C:\\Requests\\ \u0444\u0430\u0439\u043b <strong>*.req<\/strong>, \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u044b\u0439 \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0448\u0430\u0433\u0435, \u0434\u043e\u043b\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u0441\u044f &#171;<strong>C:\\Requests\\webserver.domain.ru.req<\/strong>&#171;.<\/p>\n\n\n\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u0443\u044e \u0441\u0442\u0440\u043e\u043a\u0443 \u043e\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0438\u043c\u0435\u044e\u0449\u0435\u0433\u043e \u043f\u0440\u0430\u0432\u0430 \u043d\u0430 \u0432\u044b\u0434\u0430\u0447\u0443 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 (Domain Admins \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440). \u041f\u0440\u043e\u0431\u0443\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>certreq -submit -attrib \"CertificateTemplate:WebServer\" \"C:\\Requests\\webserver.domain.ru.req\" \"C:\\Requests\\webserver.domain.ru.cer\"<\/code><\/pre>\n\n\n\n<p>\u041e\u0442\u043a\u0440\u043e\u0435\u0442\u0441\u044f \u043e\u043a\u043d\u043e \u0434\u043b\u044f \u0432\u044b\u0431\u043e\u0440\u0430 \u0446\u0435\u043d\u0442\u0440\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0432\u044b\u0431\u0438\u0440\u0430\u0435\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0439. \u0421\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043e\u043b\u0436\u0435\u043d \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f, \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c\u0441\u044f \u0432 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435, \u0430 \u0437\u0430\u0431\u0440\u0430\u0442\u044c \u0435\u0433\u043e \u043c\u043e\u0436\u043d\u043e \u0432 &#171;C:\\Requests\\webserver.domain.ru.cer&#187;. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043c\u043e\u0436\u043d\u043e \u0435\u0433\u043e \u043e\u0442\u043a\u0440\u044b\u0442\u044c \u0438 \u0443\u0431\u0435\u0434\u0438\u0442\u044c\u0441\u044f \u0447\u0442\u043e \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 <strong>Subject Alternative Name<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 4<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2.<\/strong> <\/p>\n\n\n\n<p>\u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c <strong>webserver.domain.ru.cer<\/strong> \u0438\u0437 \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u043d\u0430 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440 \u0438 \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u0438\u0440\u0443\u0435\u043c \u0432 <strong>pem<\/strong>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>openssl x509 -in webserver.domain.ru.cer -out webserver.domain.ru.pem<\/code><\/pre>\n\n\n\n<p>\u041e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c\u0441\u044f, \u0433\u0434\u0435 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c <strong>pem<\/strong> \u0438 <strong>key<\/strong> \u0444\u0430\u0439\u043b\u044b \u0434\u043b\u044f Apache2. \u042f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \/etc\/ssl\/certs\/ \u0438 \/etc\/ssl\/private\/ (\u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e \u043d\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e). \u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0435\u0441\u044f \u0444\u0430\u0439\u043b\u044b \u0442\u0443\u0434\u0430:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cp webserver.domain.ru.pem \/etc\/ssl\/certs\/webserver.domain.ru.pem\ncp webserver.domain.ru.key \/etc\/ssl\/private\/webserver.domain.ru.key<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u0428\u0430\u0433 5<\/h2>\n\n\n\n<p><strong>\u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2.<\/strong><\/p>\n\n\n\n<p>\u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0441\u0430\u0439\u0442\u0430, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 <strong>\/etc\/apache2\/sites-available\/default-ssl.conf<\/strong> \u0438 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c\/\u043c\u0435\u043d\u044f\u0435\u043c \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SSLCertificateFile     \/etc\/ssl\/certs\/webserver.domain.ru.pem\nSSLCertificateKeyFile  \/etc\/ssl\/private\/webserver.domain.ru.key<\/code><\/pre>\n\n\n\n<p>\u041f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440 <strong>systemctl restart apache2<\/strong><\/p>\n\n\n\n<p>\u041f\u0440\u043e\u0431\u0443\u0435\u043c \u043e\u0442\u043a\u0440\u044b\u0442\u044c \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0443 \u0432 \u0432\u0435\u0431 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u0438 \u0443\u0434\u043e\u0441\u0442\u043e\u0432\u0435\u0440\u044f\u0435\u043c\u0441\u044f, \u0447\u0442\u043e \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043e (\u043a\u043e\u0440\u043d\u0435\u0432\u044b\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u044b \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435).<\/p>\n\n\n\n<p>Firefox \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432, \u043c\u043e\u0436\u043d\u043e \u0447\u0435\u0440\u0435\u0437 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442, \u0438\u043b\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>about:config\nsecurity.enterprise_roots.enabled -&gt; true<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u0427\u0442\u043e \u043f\u043e\u0447\u0438\u0442\u0430\u0442\u044c<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/support.dnsimple.com\/articles\/what-is-ssl-san\/\">https:\/\/support.dnsimple.com\/articles\/what-is-ssl-san\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/help.bizagi.com\/bpm-suite\/en\/index.html?subjectaltname_support.htm\">https:\/\/help.bizagi.com\/bpm-suite\/en\/index.html?subjectaltname_support.htm<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/blog.zencoffee.org\/2013\/04\/creating-and-signing-an-ssl-cert-with-alternative-names\/\">https:\/\/blog.zencoffee.org\/2013\/04\/creating-and-signing-an-ssl-cert-with-alternative-names\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/pc.ru\/articles\/razreshaem-firefox-ispolzovat-kornevye-sertifikaty-windows\">https:\/\/pc.ru\/articles\/razreshaem-firefox-ispolzovat-kornevye-sertifikaty-windows<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u0418\u043c\u0435\u0435\u0442\u0441\u044f \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0446\u0435\u043d\u0442\u0440 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Windows Server Active Directory\u00a0Certificate\u00a0Services (AD CS). \u0417\u0430\u0434\u0430\u0447\u0430: \u0432\u044b\u0434\u0430\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441 Apache2 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430\u0445 Chrome \u0438 Edge (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 SAN \u043e\u043f\u0446\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430). \u0428\u0430\u0433 0 \u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2. \u041e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c\u0441\u044f \u0433\u0434\u0435 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0432 \u0445\u043e\u0434\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438, \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e: \/home\/administrator\/certs\/webserver.domain.ru \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c&hellip;<\/p>\n <a href=\"https:\/\/extralan.ru\/?p=3094\" title=\"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN)\" class=\"entry-more-link\"><span>Read More<\/span> <span class=\"screen-reader-text\">\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN)<\/span><\/a>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"Layout":"","footnotes":""},"categories":[14,4,218],"tags":[375,374,377,376,378],"class_list":["entry","author-jonnyquest","post-3094","post","type-post","status-publish","format-standard","category-linux","category-windows","category-218","tag-ad-ca","tag-apache2","tag-openssl","tag-san","tag-subject-alternative-name"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/extralan.ru\/?p=3094\" \/>\n<meta property=\"og:locale\" content=\"ru_RU\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru\" \/>\n<meta property=\"og:description\" content=\"\u0418\u043c\u0435\u0435\u0442\u0441\u044f \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0446\u0435\u043d\u0442\u0440 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Windows Server Active Directory\u00a0Certificate\u00a0Services (AD CS). \u0417\u0430\u0434\u0430\u0447\u0430: \u0432\u044b\u0434\u0430\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441 Apache2 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430\u0445 Chrome \u0438 Edge (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 SAN \u043e\u043f\u0446\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430). \u0428\u0430\u0433 0 \u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2. \u041e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c\u0441\u044f \u0433\u0434\u0435 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0432 \u0445\u043e\u0434\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438, \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e: \/home\/administrator\/certs\/webserver.domain.ru \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c&hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/extralan.ru\/?p=3094\" \/>\n<meta property=\"og:site_name\" content=\"ExtraLAN.ru\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-07T11:09:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-10T11:29:55+00:00\" \/>\n<meta name=\"author\" content=\"Jonny Quest\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u043e\u043c\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jonny Quest\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 \u043c\u0438\u043d\u0443\u0442\u044b\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/extralan.ru\/?p=3094\",\"url\":\"https:\/\/extralan.ru\/?p=3094\",\"name\":\"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru\",\"isPartOf\":{\"@id\":\"https:\/\/extralan.ru\/#website\"},\"datePublished\":\"2023-11-07T11:09:43+00:00\",\"dateModified\":\"2023-11-10T11:29:55+00:00\",\"author\":{\"@id\":\"https:\/\/extralan.ru\/#\/schema\/person\/32aebde038afaea65ab6c7300a21a53f\"},\"breadcrumb\":{\"@id\":\"https:\/\/extralan.ru\/?p=3094#breadcrumb\"},\"inLanguage\":\"ru-RU\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/extralan.ru\/?p=3094\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/extralan.ru\/?p=3094#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\",\"item\":\"https:\/\/extralan.ru\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/extralan.ru\/#website\",\"url\":\"https:\/\/extralan.ru\/\",\"name\":\"ExtraLAN.ru\",\"description\":\"\u0420\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0437\u0430\u043c\u0435\u0442\u043a\u0438 \u043f\u043e \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/extralan.ru\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"ru-RU\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/extralan.ru\/#\/schema\/person\/32aebde038afaea65ab6c7300a21a53f\",\"name\":\"Jonny Quest\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ru-RU\",\"@id\":\"https:\/\/extralan.ru\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/46b63f8ca4df27c7c4733a8790610b5b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/46b63f8ca4df27c7c4733a8790610b5b?s=96&d=mm&r=g\",\"caption\":\"Jonny Quest\"},\"url\":\"https:\/\/extralan.ru\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/extralan.ru\/?p=3094","og_locale":"ru_RU","og_type":"article","og_title":"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru","og_description":"\u0418\u043c\u0435\u0435\u0442\u0441\u044f \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0446\u0435\u043d\u0442\u0440 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Windows Server Active Directory\u00a0Certificate\u00a0Services (AD CS). \u0417\u0430\u0434\u0430\u0447\u0430: \u0432\u044b\u0434\u0430\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0434\u043b\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0441 Apache2 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0430\u0445 Chrome \u0438 Edge (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u0430 SAN \u043e\u043f\u0446\u0438\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430). \u0428\u0430\u0433 0 \u041d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0432\u0435\u0431 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache2. \u041e\u043f\u0440\u0435\u0434\u0435\u043b\u044f\u0435\u043c\u0441\u044f \u0433\u0434\u0435 \u0431\u0443\u0434\u0443\u0442 \u043b\u0435\u0436\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b, \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0432 \u0445\u043e\u0434\u0435 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438, \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e: \/home\/administrator\/certs\/webserver.domain.ru \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0438\u043c&hellip;","og_url":"https:\/\/extralan.ru\/?p=3094","og_site_name":"ExtraLAN.ru","article_published_time":"2023-11-07T11:09:43+00:00","article_modified_time":"2023-11-10T11:29:55+00:00","author":"Jonny Quest","twitter_card":"summary_large_image","twitter_misc":{"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e \u0430\u0432\u0442\u043e\u0440\u043e\u043c":"Jonny Quest","\u041f\u0440\u0438\u043c\u0435\u0440\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f":"2 \u043c\u0438\u043d\u0443\u0442\u044b"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/extralan.ru\/?p=3094","url":"https:\/\/extralan.ru\/?p=3094","name":"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN) - ExtraLAN.ru","isPartOf":{"@id":"https:\/\/extralan.ru\/#website"},"datePublished":"2023-11-07T11:09:43+00:00","dateModified":"2023-11-10T11:29:55+00:00","author":{"@id":"https:\/\/extralan.ru\/#\/schema\/person\/32aebde038afaea65ab6c7300a21a53f"},"breadcrumb":{"@id":"https:\/\/extralan.ru\/?p=3094#breadcrumb"},"inLanguage":"ru-RU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/extralan.ru\/?p=3094"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/extralan.ru\/?p=3094#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u0413\u043b\u0430\u0432\u043d\u0430\u044f \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430","item":"https:\/\/extralan.ru\/"},{"@type":"ListItem","position":2,"name":"\u0412\u044b\u0434\u0430\u0447\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 \u0434\u043b\u044f Apache2 \u0441 Subject Alternative Name (SAN)"}]},{"@type":"WebSite","@id":"https:\/\/extralan.ru\/#website","url":"https:\/\/extralan.ru\/","name":"ExtraLAN.ru","description":"\u0420\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0437\u0430\u043c\u0435\u0442\u043a\u0438 \u043f\u043e \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/extralan.ru\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"ru-RU"},{"@type":"Person","@id":"https:\/\/extralan.ru\/#\/schema\/person\/32aebde038afaea65ab6c7300a21a53f","name":"Jonny Quest","image":{"@type":"ImageObject","inLanguage":"ru-RU","@id":"https:\/\/extralan.ru\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/46b63f8ca4df27c7c4733a8790610b5b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/46b63f8ca4df27c7c4733a8790610b5b?s=96&d=mm&r=g","caption":"Jonny Quest"},"url":"https:\/\/extralan.ru\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/posts\/3094"}],"collection":[{"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/extralan.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3094"}],"version-history":[{"count":7,"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/posts\/3094\/revisions"}],"predecessor-version":[{"id":3106,"href":"https:\/\/extralan.ru\/index.php?rest_route=\/wp\/v2\/posts\/3094\/revisions\/3106"}],"wp:attachment":[{"href":"https:\/\/extralan.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/extralan.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/extralan.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}