You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将IP地址作为通用名用于自签名证书?解决Chrome报错问题

Fixing ERR_CERT_COMMON_NAME_INVALID for IP-Based Self-Signed Certificates

Got it, let's sort out this Chrome error for your IP-based self-signed certificate. The root cause here is that modern browsers like Chrome don't rely solely on the Common Name (CN) field anymore—they require the IP address to be explicitly listed in the Subject Alternative Name (SAN) extension of the certificate. Here's how to generate a valid certificate properly:

Method 1: Quick Single-Command Generation

If you just need a cert for a single IP address, you can generate it directly with this OpenSSL command (replace 192.168.1.100 with your actual IP):

openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 -nodes \
  -keyout ip-cert.key -out ip-cert.crt \
  -subj "/CN=192.168.1.100" \
  -addext "subjectAltName=IP:192.168.1.100" \
  -addext "keyUsage=digitalSignature,keyEncipherment" \
  -addext "extendedKeyUsage=serverAuth"

Key breakdown of the command:

  • -x509: Generates a self-signed certificate (instead of a CSR)
  • -addext "subjectAltName=IP:192.168.1.100": This is the critical line that adds your IP as a valid SAN entry—Chrome checks this first now
  • keyUsage and extendedKeyUsage: Mark the certificate as valid for server authentication, which avoids extra browser warnings

Method 2: Generate with a Config File (For Multiple IPs/Domains)

If you need to include multiple IP addresses or domain names in the certificate, use an OpenSSL config file for more flexibility:

  1. Create a file named openssl-ip.cnf with this content (replace 192.168.1.100 with your IP; add more IP:x.x.x.x entries to subjectAltName if needed):
[req]
default_bits       = 4096
distinguished_name = req_distinguished_name
req_extensions     = req_ext
prompt             = no

[req_distinguished_name]
CN = 192.168.1.100

[req_ext]
subjectAltName = IP:192.168.1.100
keyUsage = digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
  1. Run this command to generate the certificate and key:
openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 -nodes \
  -keyout ip-cert.key -out ip-cert.crt \
  -config openssl-ip.cnf

Final Step: Trust the Certificate in Chrome

Even with a valid SAN entry, Chrome will warn you unless you mark the certificate as trusted:

  • Open Chrome and go to Settings > Privacy and security > Security > Manage certificates
  • Switch to the Trusted Root Certification Authorities tab
  • Click Import, select your generated ip-cert.crt file, and follow the prompts to add it to the trusted store
  • Restart Chrome to apply the changes

Why Your Original Certificate Failed

Starting from Chrome 58, the browser stopped using the CN field for identity verification. Even if you set the CN to an IP address, Chrome will ignore it unless the IP is explicitly added as an IP-type SAN entry in the certificate extensions. That's exactly why you saw the ERR_CERT_COMMON_NAME_INVALID error.

内容的提问来源于stack exchange,提问作者Rizwan Pasha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:19:45