The same logic was duplicated in three places. Factor it out so that we can add further fallbacks in a single place.
Without a CN the self signed certificate is considered invalid by chrome. You can check with: openssl x509 -in cert.pem -subject -noout