📋 SAN List Builder

Enter one domain or IP address per line to build the Subject Alternative Name (SAN) extension string — required by modern browsers for every name a TLS certificate should cover.

How each line is classified

The builder works entirely in the page. It trims every line, drops the blank ones, and tags each survivor: four dotted numbers all 255 or less, or anything containing a colon and only hex digits, becomes IP:; everything else becomes DNS:. The four default lines produce:

DNS:example.com,DNS:www.example.com,DNS:api.example.com,IP:203.0.113.10

The second output box is the same list for an openssl.cnf section, which needs the subjectAltName = prefix and tolerates the spaces after each comma. Wildcards pass straight through as DNS entries.

Enter bare names only. A line like https://example.com or example.com:443 is not recognised as an address and comes out as a DNS entry containing the scheme or port, which no CA will accept.

Where the string goes

openssl req -new -key private.key -out request.csr \
  -addext "subjectAltName=DNS:example.com,DNS:www.example.com"

# or in openssl.cnf, referenced with -reqexts v3_req
[ v3_req ]
subjectAltName = DNS:example.com, DNS:www.example.com

Whatever you put in the Common Name must also appear in this list. Chrome stopped reading CN for hostname matching in 2017 and the others followed, so a name that exists only in the subject is a name the certificate does not cover.

Frequently asked questions

Does a wildcard certificate cover the bare domain?

No. *.example.com matches one label in that position - www and api but not example.com itself, and not a.b.example.com. List both *.example.com and example.com.

Can a public certificate cover an IP address?

Only a globally routable one that you can prove control of, and few CAs offer it. Private ranges like 10.0.0.0/8 and 192.168.0.0/16 have not been issuable publicly since 2016, so an internal address needs your own CA.

My certificate came back without the SANs I asked for. Why?

Either the CA applied its own profile - requested extensions are advisory - or you signed it yourself with openssl x509 -req, which discards CSR extensions unless you pass -copy_extensions copy or supply them again with -extfile.