如何将IP地址作为通用名用于自签名证书?解决Chrome报错问题
Got it, let's sort out this Chrome error for your IP-based self-signed certificate. The root cause here is that modern browsers like Chrome don't rely solely on the Common Name (CN) field anymore—they require the IP address to be explicitly listed in the Subject Alternative Name (SAN) extension of the certificate. Here's how to generate a valid certificate properly:
Method 1: Quick Single-Command Generation
If you just need a cert for a single IP address, you can generate it directly with this OpenSSL command (replace 192.168.1.100 with your actual IP):
openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 -nodes \ -keyout ip-cert.key -out ip-cert.crt \ -subj "/CN=192.168.1.100" \ -addext "subjectAltName=IP:192.168.1.100" \ -addext "keyUsage=digitalSignature,keyEncipherment" \ -addext "extendedKeyUsage=serverAuth"
Key breakdown of the command:
-x509: Generates a self-signed certificate (instead of a CSR)-addext "subjectAltName=IP:192.168.1.100": This is the critical line that adds your IP as a valid SAN entry—Chrome checks this first nowkeyUsageandextendedKeyUsage: Mark the certificate as valid for server authentication, which avoids extra browser warnings
Method 2: Generate with a Config File (For Multiple IPs/Domains)
If you need to include multiple IP addresses or domain names in the certificate, use an OpenSSL config file for more flexibility:
- Create a file named
openssl-ip.cnfwith this content (replace192.168.1.100with your IP; add moreIP:x.x.x.xentries tosubjectAltNameif needed):
[req] default_bits = 4096 distinguished_name = req_distinguished_name req_extensions = req_ext prompt = no [req_distinguished_name] CN = 192.168.1.100 [req_ext] subjectAltName = IP:192.168.1.100 keyUsage = digitalSignature, keyEncipherment extendedKeyUsage = serverAuth
- Run this command to generate the certificate and key:
openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 -nodes \ -keyout ip-cert.key -out ip-cert.crt \ -config openssl-ip.cnf
Final Step: Trust the Certificate in Chrome
Even with a valid SAN entry, Chrome will warn you unless you mark the certificate as trusted:
- Open Chrome and go to Settings > Privacy and security > Security > Manage certificates
- Switch to the Trusted Root Certification Authorities tab
- Click Import, select your generated
ip-cert.crtfile, and follow the prompts to add it to the trusted store - Restart Chrome to apply the changes
Why Your Original Certificate Failed
Starting from Chrome 58, the browser stopped using the CN field for identity verification. Even if you set the CN to an IP address, Chrome will ignore it unless the IP is explicitly added as an IP-type SAN entry in the certificate extensions. That's exactly why you saw the ERR_CERT_COMMON_NAME_INVALID error.
内容的提问来源于stack exchange,提问作者Rizwan Pasha

