Click here to get back home

add UPN in certificate Request

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
add UPN in certificate Request Mixer76 02-19-2007
Posted by Mixer76 on February 19, 2007, 7:21 am
Please log in for more thread options
Hello!

I'm developing an application which requests certificates at the Microsoft
CA (Windows 2003) via the xenroll interface.
I use a copy of the "SmartCardLogon" Template for my requests and have set
up the "Supply in the request" option for subject name. Up to this point
everything works fine.
Now my problem is, that I want to set up a Alternative Subject Name/ UPN
which will be included in my certificate. I've tried several ways to insert
the UPN into my request but the CA seems to ignore this value and issues a
certificate without a UPN. Can anybody tell me how to set this UPN?

Thanks!

Michael



Posted by Chipeater on February 19, 2007, 4:02 pm
Please log in for more thread options
Michael,
As a start, try applying the following setting to enable scripted
submission of a subject alternative name (SAN). It's supposed to only
be necessary on a Win2K CA, but I found that I needed it on a Win2K3
CA.

"CERTUTIL -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2"

If you then run "CERTUTIL -getreg policy" you should see the change
has been made.

I'm assuming that you are using an inf file and have a
[RequestAttributes] section where you are specifying a SAN.

Finally, if this still doesn't work, try changing the RequestType to
CMC.

Hope this helps, Dave


Similar ThreadsPosted
Create Certificate Request for Windows2003 certificate authority without using website March 22, 2006, 8:07 am
Cannot request computer certificate. January 6, 2006, 1:00 pm
PKI Certificate request from another forest September 14, 2006, 4:28 pm
Specifying publication location in the certificate request October 8, 2005, 2:03 am
Certificate Services could not process request January 2, 2007, 9:31 pm
Online request of a certificate with CA in another domain January 26, 2007, 11:39 am
PKI difference between "Advanced Certificate Request" May 28, 2008, 10:38 am
Request certificate to a CA in Windows server 2003 January 26, 2007, 12:44 pm
automatic certificate request GPO VS Auto enroll February 19, 2008, 1:50 pm
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap