There seems to be a lot of misplaced rage … instead, direct that ire at the vendors that don’t support automation. The best time was 5 years ago, the second best time is now.
@sirus@DennisF If the TLS session isn’t new, it could have validated the cert prior to expiration and used session resumption to continue with the old TLS context. Browsers can cache the cert and just show it when asked.
Why would you use CommonName inside an OtherName in a SubjectAltName, for validation that a node is part of a collection of nodes‽ (DNSNames are still used for validation that you’re connecting to the correct server, at least if you don’t turn that off)
https://t.co/m0wIul00oP