$ 0 0 this setting was necessary to submit SAN as attribute, not authenticated extension. This setting opens a big hole in your PKI, because any request can pass arbitrary SAN value. And impersonate any user.