How to add a custom Subject Alternative Name to a fixed certificate request at CA level?
we have fixed certificate request third party device. certificate request doesn't contain subject alternative name.
is possible to add subject alternative name @ ca level in the signing process itself?
many commercial cas offer step wenn upload custom certificate request in binary format , afterwards can choose add custom subject alternative name before actual signing occurs.
the convenient way described in article: http://en-us.sysadmins.lv/lists/posts/post.aspx?id=11
p.s. not use guides recommend enable san attribute on ca server, because insecure way , may lead fraud certificate issuance ca.
my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
check out new: powershell fciv tool.
Windows Server > Security
Comments
Post a Comment