add https://go-review.googlesource.com/c/36696
"crypto/x509: ignore CN if SAN extension present"
to the release notes.
Fixes #21289
Change-Id: Ifa184d3816806a8da3c67b68476c923329acf13e
Reviewed-on: https://go-review.googlesource.com/53030
Reviewed-by: Ian Lance Taylor <iant@golang.org>
populated.
</p>
+ <p><!-- CL 36696 -->
+
+ If any SAN extension, including with no DSN names, is present
+ in the certificate, then the Common Name from
+ <a href="#pkg/crypto/x509/#Certificate.Subject"><code>Subject</code>code></a> is ignored.
+ In previous releases, the code tested only whether DNS-name SANs were
+ present in a certificate.
+ </p>
+
</dl><!-- crypto/x509 -->
<dl id="database/sql"><dt><a href="/pkg/database/sql/">database/sql</a></dt>