Isn’t it that client certificate SAN needs to have
UPN should be encoded as an “otherName” value in the SAN with a type-id of 1.3.6.1.4.1.311.20.2.3 (Microsoft UPN); not a dNSName.

Isn’t it that client certificate SAN needs to have
UPN should be encoded as an “otherName” value in the SAN with a type-id of 1.3.6.1.4.1.311.20.2.3 (Microsoft UPN); not a dNSName.
