san – OpenSSL GENERAL_NAME:bad ip address set in [alt_names]

I am getting this error in my device:

javax.net.ssl.SSLException: hostname in certificate didn't match: <ec2-5-43-58-857.us-east-2.compute.amazonaws.com> != <na>

So I did some research and found I could set alternative IP address in an OpenSSL config and then generate new keys/certs.

This is my config

[ubuntu@ip-172-31-25-95 ~] 2020-10-09 14:19:07$ cat san.cfg
[req]
default_bits  = 2048
distinguished_name = req_distinguished_name
req_extensions = req_ext
x509_extensions = v3_req
prompt = no
[req_distinguished_name]
countryName = XX
stateOrProvinceName = N/A
localityName = N/A
organizationName = Self-signed certificate
commonName = 120.0.0.1: Self-signed certificate
[req_ext]
subjectAltName = @alt_names
[v3_req]
subjectAltName = @alt_names
[alt_names]
IP.1 = ec2-5-43-58-857.us-east-2.compute.amazonaws.com

But when I run:

sudo openssl req -x509 -days 36500 -newkey rsa:2048 -keyout ./key_elastic.pem -out ./cert_elastic.pem -config ./san.cfg

I get this error:

140515677422016:error:220A4076:X509 V3 routines:a2i_GENERAL_NAME:bad ip address:../crypto/x509v3/v3_alt.c:457:value=ec2-5-43-58-857.us-east-2.compute.amazonaws.com
140515677422016:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in extension:../crypto/x509v3/v3_conf.c:47:name=subjectAltName, value=@alt_names

Mind you, everything was working fine until I switched to an elastic IP address for server. I made new keys they same way I did before. But then I got the first device error I mentions at the top of the post.

certificates – CA cert with many Subject Alternative Name (SAN) entries, versus individual certs in public production?

The idea of using SANs makes sense if you have, for example, one web server which takes care of several smaller websites (e.g. example.com and internal.example.com). In this case, having one certificate per web server, with SANs for each website reduces the amount of configuration overhead.

However, once you start to create what I like to call a “megacertificate”, meaning once certificate with uncountably many SANs, you will run into problems. This certificate, and its associated private key, will likely be distributed to many many different servers, meaning that your private key will be in many different places.

This in turn means that the attack surface has now grown exponentially, as it means one compromised server can now compromise all domains, even if they are on different physical servers.

(+) its easier to standardise the certificate options (i.e. hashing/cyphers) on a shared cert

This is false. First of all, the certificate itself does not define any cryptographic ciphers to be used by TLS, only which cryptographic operations are necessary to validate the certificate.

This means that two different physical servers – let’s call them alice.com and bob.com – can use the same certificate (with SAN entries for both), and yet still support completely different sets of ciphers. alice.com could support only state-of-the-art ciphers and bob.com may be stuck using insecure legacy ciphers for interoperability reasons.

The only valid reason I can think of at the moment why you might use SANs – aside from convenience during manual setup – is that an appliance or application may not support uploading several different certificates, yet needs to serve different domains.

automobiles – For how long can one leave one’s car parked in San Diego Old Town’s free parking lots?

Midavalo mentioned that there exist some free parking lots in Old Town in San Diego near the trolley that goes to San Ysidro border crossing. E.g. https://www.oldtownsandiegoguide.com/dayofthedead/parking2.html

Free and ample parking is available at the Caltrans parking lot at 4050 Taylor Street. It is free and open to the public all day both Saturday and Sunday and Monday after 5:00. It’s a great place to park, as the event begins just across the street!

https://www.tripadvisor.com/ShowTopic-g60750-i41-k5242108-Free_Cheaper_Parking_in_Old_Town-San_Diego_California.html mentions other free parking spots.

For how long can one leave one’s car parked in such free parking lots? 24 hours, a few days/weeks/months?

developer program – Can I use Apple’s San Francisco font (and other fonts) in my own text editor?

No.

As you mention, you can do it technically, but the license I reviewed appears to not grant anyone a license to use this work in personal projects. Some good people agree with me as well. As a developer, you will want to get good legal advice on licensing – what we think on this internet site isn’t likely to be prudent legal advice. Even if I was a lawyer, I’m certainly not your lawyer.

Read your legal agreement carefully. If you wish to license the typeface, you could ask Apple for (or your business manager to acquire) that license or how much they would charge for such a personal use license.

[Vn5socks.net] Auto update 24/7 – Good socks 12h45 PM


LIVE ~ 72.11.148.222:56533 | 0.218 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 101.51.108.65:9999 | 0.162 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 64.227.6.113:40001 | 0.251 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.287 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 220.126.225.249:10111 | 0.083 | Incheon | 12 | Unknown | Korea, Republic of | Checked at vn5socks.net
LIVE ~ 68.183.20.86:40001 | 0.272 | Granada Hills | CA | Unknown | United States | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.318 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 58.253.154.109:1081 | 0.093 | Guangzhou | 30 | Unknown | China | Checked at vn5socks.net
LIVE ~ 181.129.7.202:6699 | 0.449 | Medell�n | 02 | Unknown | Colombia | Checked at vn5socks.net
LIVE ~ 47.49.12.165:37885 | 0.29 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 13.77.137.22:1081 | 0.241 | Norwalk | CT | 06850 | United States | Checked at vn5socks.net
LIVE ~ 142.93.202.166:40001 | 0.338 | Unknown | Unknown | Unknown | Canada | Checked at vn5socks.net
LIVE ~ 116.202.185.45:1181 | 0.299 | Mumbai | 16 | Unknown | India | Checked at vn5socks.net
LIVE ~ 206.189.158.28:29993 | 0.076 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 220.126.225.246:10166 | 0.165 | Incheon | 12 | Unknown | Korea, Republic of | Checked at vn5socks.net
LIVE ~ 68.183.20.134:40001 | 0.344 | Granada Hills | CA | Unknown | United States | Checked at vn5socks.net
LIVE ~ 173.254.222.162:1090 | 0.203 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 108.61.75.207:9000 | 0.346 | Piscataway | NJ | 08854 | United States | Checked at vn5socks.net


FireHeaven
Reviewed by FireHeaven on
.
[Vn5socks.net] Auto update 24/7 – Good socks 12h45 PM
LIVE ~ 72.11.148.222:56533 | 0.218 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 101.51.108.65:9999 | 0.162 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 64.227.6.113:40001 | 0.251 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.287 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 220.126.225.249:10111 | 0.083 | Incheon | 12 |

Rating: 5



.

Is the San Ysidro PedWest crossing closed?

I read:

  • https://bwt.cbp.gov/details/09250407/PED (mirror) says "Current Wait: Lanes Closed" and "Hours of Operation: 24 hrs/day Date: 9/25/2020", and the graph displays and flat 0-minute waiting time throughout the day, which seems to indicate all lanes are closed hrs/day.
  • https://goo.gl/maps/Vhv37YFhgAkqi3sb7 (mirror) says it is opened between 4 AM to 10 PM.
  • https://www.10news.com/news/local-news/new-coronavirus-testing-side-opening-along-u-s-mexico-border (mirror) (published on 2020-08-09) seems to imply it was open by the time the article was published.
  • https://www.newsbreak.com/california/san-diego/news/1541178199258/pedwest-crossing-temporarily-closed-as-part-of-changes-at-the-california-mexico-border
    (mirror) (published on 2020-04-04) says "U.S. Customs and Border Protection has made changes at ports of entry along the California-Mexico border, including the temporary closure of the PedWest pedestrian crossing, in response to decreases in traffic since the coronavirus-related restrictions to non-essential travel took place."

I am getting confused. Is the San Ysidro PedWest crossing currently closed? If so, when is it scheduled to reopen, and if not what are the hours of operations?

[Vn5socks.net] Auto update 24/7 – Good socks 10h40 PM


LIVE ~ 206.189.158.28:47510 | 0.036 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 159.89.237.201:40001 | 0.333 | Vancouver | BC | v7y1j7 | Canada | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.339 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.32 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.366 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 68.183.20.134:40001 | 0.308 | Granada Hills | CA | Unknown | United States | Checked at vn5socks.net
LIVE ~ 173.254.222.162:1090 | 0.289 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 68.183.20.86:40001 | 0.328 | Granada Hills | CA | Unknown | United States | Checked at vn5socks.net
LIVE ~ 104.131.111.138:40001 | 0.327 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 45.63.114.19:40001 | 0.266 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 109.120.158.13:30038 | 0.315 | Unknown | Unknown | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 80.233.134.119:9300 | 0.335 | Unknown | Unknown | Unknown | Latvia | Checked at vn5socks.net
LIVE ~ 176.122.61.247:40926 | 0.424 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 144.202.30.219:40001 | 0.242 | Three Springs | PA | 17264 | United States | Checked at vn5socks.net
LIVE ~ 64.225.45.240:40001 | 0.184 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 68.183.26.102:40001 | 0.345 | San Jose | CA | 95132 | United States | Checked at vn5socks.net
LIVE ~ 47.75.182.33:1081 | 0.034 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 161.35.154.78:40001 | 0.382 | Mahwah | NJ | 07430 | United States | Checked at vn5socks.net


FireHeaven
Reviewed by FireHeaven on
.
[Vn5socks.net] Auto update 24/7 – Good socks 10h40 PM
LIVE ~ 206.189.158.28:47510 | 0.036 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 159.89.237.201:40001 | 0.333 | Vancouver | BC | v7y1j7 | Canada | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.339 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.32 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.366 | Atlanta | GA | 30303 |

Rating: 5



.

[Vn5socks.net] Auto update 24/7 – Good socks 4h45 PM


LIVE ~ 216.144.230.233:15993 | 0.192 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.285 | Moscow | 48 | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.28 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 144.202.30.219:40001 | 0.238 | Three Springs | PA | 17264 | United States | Checked at vn5socks.net
LIVE ~ 68.183.26.102:40001 | 0.247 | San Jose | CA | 95132 | United States | Checked at vn5socks.net
LIVE ~ 161.35.154.78:40001 | 0.293 | Mahwah | NJ | 07430 | United States | Checked at vn5socks.net
LIVE ~ 47.100.240.237:21080 | 0.203 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.264 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 109.120.158.13:30038 | 0.381 | Unknown | Unknown | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.248 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 64.225.45.240:40001 | 0.192 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 159.89.237.201:40001 | 0.258 | Vancouver | BC | v7y1j7 | Canada | Checked at vn5socks.net
LIVE ~ 72.11.148.222:56533 | 0.271 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 206.189.158.28:47510 | 0.202 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 209.97.182.201:9070 | 0.284 | Alameda | CA | 94501 | United States | Checked at vn5socks.net
LIVE ~ 45.63.114.19:40001 | 0.241 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 47.75.182.33:1081 | 0.035 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net


FireHeaven
Reviewed by FireHeaven on
.
[Vn5socks.net] Auto update 24/7 – Good socks 4h45 PM
LIVE ~ 216.144.230.233:15993 | 0.192 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.285 | Moscow | 48 | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.28 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 144.202.30.219:40001 | 0.238 | Three Springs | PA | 17264 | United States | Checked at vn5socks.net
LIVE ~ 68.183.26.102:40001 | 0.247 | San Jose | CA

Rating: 5



.

[Vn5socks.net] Auto update 24/7 – Good socks 5h00 PM


LIVE ~ 1.0.213.32:9999 | 0.155 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 216.144.230.233:15993 | 0.192 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.285 | Moscow | 48 | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.28 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 144.202.30.219:40001 | 0.238 | Three Springs | PA | 17264 | United States | Checked at vn5socks.net
LIVE ~ 68.183.26.102:40001 | 0.247 | San Jose | CA | 95132 | United States | Checked at vn5socks.net
LIVE ~ 161.35.154.78:40001 | 0.293 | Mahwah | NJ | 07430 | United States | Checked at vn5socks.net
LIVE ~ 47.100.240.237:21080 | 0.203 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.264 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 109.120.158.13:30038 | 0.381 | Unknown | Unknown | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.248 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 64.225.45.240:40001 | 0.192 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 159.89.237.201:40001 | 0.258 | Vancouver | BC | v7y1j7 | Canada | Checked at vn5socks.net
LIVE ~ 72.11.148.222:56533 | 0.271 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 206.189.158.28:47510 | 0.202 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 209.97.182.201:9070 | 0.284 | Alameda | CA | 94501 | United States | Checked at vn5socks.net
LIVE ~ 45.63.114.19:40001 | 0.241 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 47.75.182.33:1081 | 0.035 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net


FireHeaven
Reviewed by FireHeaven on
.
[Vn5socks.net] Auto update 24/7 – Good socks 5h00 PM
LIVE ~ 1.0.213.32:9999 | 0.155 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 216.144.230.233:15993 | 0.192 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.285 | Moscow | 48 | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.28 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 144.202.30.219:40001 | 0.238 | Three Springs | PA |

Rating: 5



.

[Vn5socks.net] Auto update 24/7 – Good socks 12h25 PM


LIVE ~ 216.144.230.233:15993 | 0.187 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 1.0.213.32:9999 | 0.159 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.29 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 47.100.240.237:21080 | 0.23 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.264 | Moscow | 48 | Unknown | Russian Federation | Checked at vn5socks.net
LIVE ~ 64.225.45.240:40001 | 0.188 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 72.11.148.222:56533 | 0.227 | Los Angeles | CA | 90014 | United States | Checked at vn5socks.net
LIVE ~ 167.172.159.177:40001 | 0.339 | Stevenage | F8 | Unknown | United Kingdom | Checked at vn5socks.net
LIVE ~ 54.36.221.87:25527 | 0.27 | Woodbridge | NJ | 07095 | United States | Checked at vn5socks.net
LIVE ~ 206.189.158.28:47510 | 0.034 | San Mateo | CA | 94404 | United States | Checked at vn5socks.net
LIVE ~ 68.183.26.102:40001 | 0.248 | San Jose | CA | 95132 | United States | Checked at vn5socks.net
LIVE ~ 64.225.64.126:40001 | 0.298 | Atlanta | GA | 30303 | United States | Checked at vn5socks.net
LIVE ~ 45.63.114.19:40001 | 0.264 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net
LIVE ~ 181.129.7.202:6699 | 0.396 | Medell�n | 02 | Unknown | Colombia | Checked at vn5socks.net
LIVE ~ 5.56.61.183:28152 | 0.254 | Unknown | Unknown | Unknown | Spain | Checked at vn5socks.net
LIVE ~ 47.75.182.33:1081 | 0.037 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 96.44.133.110:58690 | 0.184 | Agoura Hills | CA | Unknown | United States | Checked at vn5socks.net
LIVE ~ 45.77.97.106:35456 | 0.241 | Unknown | Unknown | Unknown | Unknown | Checked at vn5socks.net


FireHeaven
Reviewed by FireHeaven on
.
[Vn5socks.net] Auto update 24/7 – Good socks 12h25 PM
LIVE ~ 216.144.230.233:15993 | 0.187 | Van Nuys | CA | 91411 | United States | Checked at vn5socks.net
LIVE ~ 1.0.213.32:9999 | 0.159 | Unknown | Unknown | Unknown | Thailand | Checked at vn5socks.net
LIVE ~ 206.81.3.245:40001 | 0.29 | Oakland | CA | 94612 | United States | Checked at vn5socks.net
LIVE ~ 47.100.240.237:21080 | 0.23 | Ottawa | ON | k1y4h7 | Canada | Checked at vn5socks.net
LIVE ~ 188.120.245.247:12432 | 0.264 | Moscow | 48 | Unknown | Russian

Rating: 5



.