I ran into the following error:
The path could not be validated because the end-entity certificate contains the following unsupported critical extension: subject_alt_name
SubjectAltName extension must critical if the Subject field is empty (rfc). It is often critical for non-TLS certificate, for example TPM Endorsement Key certificates.