// RFC 6125, section 6.4.4. says that client MUST not seek a match // for CN if a dns dNSName is found.