Can't make the Enhanced key usage extention critical


hi

i testing ca functionality in windows server 2008 see if meets a specific set of requirements.
during testing have encountererd following problem:

i have not been able mark enhanced key usage extention critical. when check option during certificate creation results in application policies extention being marked critical , not enhanced key usage extention. problem requirements states extended key usage extention (oid 2.5.29.37) shal marked critical.

is possible make extention critical? , possible add enhanced key usage extention in stead of adding both enhanced key usage , application policies exetntions?

hi,

i hadn't search lot not find way make extended key usage critical through ui (certificate templates), can using adsiedit. careful though, adsiedit powerful tool.

navigate services node, public key services , certificate templates. pick certificate template , select properties.

according http://msdn.microsoft.com/en-us/library/ms679119(vs.85).aspx pkicriticalextensions contains list of extensions should marked critical. if add there 2.5.29.37 extended key usage critical.

once again careful adsiedit , make sure backup template before editing.

hth

martin rublik 


Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client