Can't make the Enhanced key usage extention critical
hi
i testing ca functionality in windows server 2008 see if meets a specific set of requirements.
during testing have encountererd following problem:
i have not been able mark enhanced key usage extention critical. when check option during certificate creation results in application policies extention being marked critical , not enhanced key usage extention. problem requirements states extended key usage extention (oid 2.5.29.37) shal marked critical.
is possible make extention critical? , possible add enhanced key usage extention in stead of adding both enhanced key usage , application policies exetntions?
i testing ca functionality in windows server 2008 see if meets a specific set of requirements.
during testing have encountererd following problem:
i have not been able mark enhanced key usage extention critical. when check option during certificate creation results in application policies extention being marked critical , not enhanced key usage extention. problem requirements states extended key usage extention (oid 2.5.29.37) shal marked critical.
is possible make extention critical? , possible add enhanced key usage extention in stead of adding both enhanced key usage , application policies exetntions?
hi,
i hadn't search lot not find way make extended key usage critical through ui (certificate templates), can using adsiedit. careful though, adsiedit powerful tool.
navigate services node, public key services , certificate templates. pick certificate template , select properties.
according http://msdn.microsoft.com/en-us/library/ms679119(vs.85).aspx pkicriticalextensions contains list of extensions should marked critical. if add there 2.5.29.37 extended key usage critical.
once again careful adsiedit , make sure backup template before editing.
hth
martin rublik
i hadn't search lot not find way make extended key usage critical through ui (certificate templates), can using adsiedit. careful though, adsiedit powerful tool.
navigate services node, public key services , certificate templates. pick certificate template , select properties.
according http://msdn.microsoft.com/en-us/library/ms679119(vs.85).aspx pkicriticalextensions contains list of extensions should marked critical. if add there 2.5.29.37 extended key usage critical.
once again careful adsiedit , make sure backup template before editing.
hth
martin rublik
Windows Server > Security
Comments
Post a Comment