📋 SAN List Builder
Enter one domain or IP address per line to build the Subject Alternative Name (SAN) extension string — required by modern browsers for every name a TLS certificate should cover.
How each line is classified
The builder works entirely in the page. It trims every line, drops the blank ones,
and tags each survivor: four dotted numbers all 255 or less, or anything containing
a colon and only hex digits, becomes IP:; everything else becomes
DNS:. The four default lines produce:
DNS:example.com,DNS:www.example.com,DNS:api.example.com,IP:203.0.113.10
The second output box is the same list for an openssl.cnf section,
which needs the subjectAltName = prefix and tolerates the spaces after
each comma. Wildcards pass straight through as DNS entries.
https://example.com
or example.com:443 is not recognised as an address and comes out as a
DNS entry containing the scheme or port, which no CA will accept.Where the string goes
openssl req -new -key private.key -out request.csr \
-addext "subjectAltName=DNS:example.com,DNS:www.example.com"
# or in openssl.cnf, referenced with -reqexts v3_req
[ v3_req ]
subjectAltName = DNS:example.com, DNS:www.example.com
Whatever you put in the Common Name must also appear in this list. Chrome stopped reading CN for hostname matching in 2017 and the others followed, so a name that exists only in the subject is a name the certificate does not cover.
Frequently asked questions
Does a wildcard certificate cover the bare domain?
No. *.example.com matches one label in that position - www and api
but not example.com itself, and not a.b.example.com. List both
*.example.com and example.com.
Can a public certificate cover an IP address?
Only a globally routable one that you can prove control of, and few CAs offer it. Private ranges like 10.0.0.0/8 and 192.168.0.0/16 have not been issuable publicly since 2016, so an internal address needs your own CA.
My certificate came back without the SANs I asked for. Why?
Either the CA applied its own profile - requested extensions are advisory - or
you signed it yourself with openssl x509 -req, which discards CSR
extensions unless you pass -copy_extensions copy or supply them
again with -extfile.