Click here to get back home

Editing Basic Contraints / Certificate Policies

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Editing Basic Contraints / Certificate Policies Aumy 10-06-2008
Posted by Aumy on October 6, 2008, 3:44 am
Please log in for more thread options


Hello everybody,

I so far unsuccessfully tried to set the basic contraints option in my
issuing CA after I set up the CA. Is there a certutil command which is able
to set this attribute so each certificate I issue with this CA has this
basic contraints attribute?

Is there a certutil command with which I can add a user notice text such as
"This certificate is for testing purpose only, ..." in the Certificate
Policies attribute (or somewhere else in the certificate)?

Thanks, Aumy



Posted by Brian Komar \(MVP\) on October 6, 2008, 6:16 am
Please log in for more thread options


These two options are defined in the capolicy.inf file and must be in place
*before* you install the CA certificate.
You cannot inject them into a CA certificate after creation, as this would
break the signature on teh certificate.
See the Best Practices white paper available at www.microsoft.com/pki
Brian

show/hide quoted text


Posted by Aumy on October 6, 2008, 10:48 am
Please log in for more thread options


Hi Brian,

thanks so far. I know, if you "edit" a certificate (in comparison to a
request), this would break the signature. This was clear to me.

However, I found a way to edit basicconstraints after I set up the (offline)
root-CA by the following command which I performed on the root-CA prior
"importing" the request into the root-CA:

certreq -policy policyfile.inf old.req new.req

where policyfile.inf contains something like...

[BasicConstraintsExtension]
pathlength = 0
critical = true

With this command, I'm able to "edit" the basicconstraints setting of the
certificates of my (online) issuing-CAs. As far as I know this is the only
way to achieve that the root-CA certificate does not contain any
show/hide quoted text
proposed, my root-CA certificate would have the same basicconstraints
setting...

Now I need a way the "edit" the basicconstraints setting of my issuing-CA so
that these settings are added to each endentity certificate. Unfortunately I
didn't place any basicconstrains setting in the capolicy.inf file before I
set up the CA. Do you know any command (certutil...) to add basicconstraints
*after* you set up the CA?

Same with "user notice text" in the Certificate Policies attribute. I'm able
with the same command as above to add user notice text in the issuing-CA
certificate. But for my endentity certificates, I don't know a way to add
such a text due to the fact that there are no request files to modify. The
certificate tempalte editor does not allow to add any user notice text into
the Certificate Policies attribute (Issuance Policies)...

Do you have any ideas? Thanks in advance,
Aumy


show/hide quoted text



Similar ThreadsPosted
Best practices for mass editing of NTFS settings on file server? September 15, 2009, 3:42 am
basic VPN question March 18, 2007, 8:28 am
Basic IPSec question. November 3, 2006, 3:46 pm
Basic Sec Template Design November 6, 2006, 7:24 am
basic firewall with TCP IP filtering March 19, 2007, 7:41 pm
SID histroy and basic authentication March 21, 2008, 8:04 am
Please recommend good basic Win Server 2003 R2 security book(s) February 16, 2008, 12:38 pm
Cisco 1300 series wireless access point/bridge Vs Linksys WAP54GPE Access Point Anyone know the basic pros & cons? November 28, 2007, 3:34 pm
policies September 12, 2005, 9:16 am
RAS and VPN policies - help March 15, 2007, 10:10 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy