Skip to main content

EnableCommonNameFallbackForLocalAnchors

Allow certificates issued by local trust anchors without subjectAlternativeName extension - EnableCommonNameFallbackForLocalAnchors​

When this setting is enabled, Google Chrome will use the commonName of a server certificate to match a hostname if the certificate is missing a subjectAlternativeName extension, as long as it successfully validates and chains to a locally-installed CA certificates.

Note that this is not recommended, as this may allow bypassing the nameConstraints extension that restricts the hostnames that a given certificate can be authorized for.

If this policy is not set, or is set to false, server certificates that lack a subjectAlternativeName extension containing either a DNS name or IP address will not be trusted.

  • True = Allow certificates lacking a subjectAlternativeName extension when issued by local trust anchors
  • False = Disallow certificates lacking a subjectAlternativeName extension

Data Type:

Boolean

Supported features:

  • Dynamic Policy Refresh: True
  • Per Profile: False