Thanks, decided to use one config file since I don't want to sync two different files and from the command line for certs I specify the Subj information and works fine creating a child of the CA with different CN. Got everything I needed for the host I was interesting in testing with.
Subject: C=US, ST=North Carolina, O=IBM Corporation, CN=192.168.2.16 X509v3 extensions: X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: Digital Signature, Non Repudiation, Key Encipherment X509v3 Extended Key Usage: OCSP Signing Netscape Cert Type: SSL Client, SSL Server -- View this message in context: http://openssl.6102.n7.nabble.com/Config-file-subjectAltName-and-This-certificate-is-not-valid-host-name-mismatch-tp46290p46372.html Sent from the OpenSSL - User mailing list archive at Nabble.com. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager majord...@openssl.org