- In verify-full> mode, the cn> (Common Name) attribute
- of the certificate is matched against the host name. If the cn>
- attribute starts with an asterisk (*>), it will be treated as
- a wildcard, and will match all characters except> a dot
+ In verify-full> mode, the host name is matched against the
+ certificate's Subject Alternative Name attribute(s), or against the
+ Common Name attribute if no Subject Alternative Name of type dNSName is
+ present. If the certificate's name attribute starts with an asterisk
+ (*>), the asterisk will be treated as
+ a wildcard, which will match all characters except> a dot
(.>). This means the certificate will not match subdomains.
If the connection is made using an IP address instead of a host name, the
IP address will be matched (without doing any DNS lookups).