A method to bypass SSL certificate name vs. host name verification via NUL
('\0') character embedded in X509 certificate's CommonName or subjectAltName
was presented at Black Hat USA 2009:
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike
This issue was originally reported for Firefox / NSS, but it affects GnuTLS' gnutls_x509_crt_check_hostname() too.
A method to bypass SSL certificate name vs. host name verification via NUL ('\0') character embedded in X509 certificate's CommonName or subjectAltName was presented at Black Hat USA 2009: http://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html#Marlinspike This issue was originally reported for Firefox / NSS, but it affects GnuTLS' gnutls_x509_crt_check_hostname() too.