Jump to content

Windows Certificate Authority. Automatically Add CN and Subject Alternate Name?


Recommended Posts

Posted

Hello,

 

When issuing a certificate if you do not add the CN to a Subject Alternate Name (SAN) you get this problem in Google Chrome - http://www.edugeek.net/forums/internet-related-filtering-firewall/183552-chrome-ssl-certifcate-error.html

 

We are using a Windows CA for our internal certificates. Is it possible to get this CA to automatically populate the SAN with the CN information to avoid this problem please? I am finding some packages are not doing this in the CSR (Unifi for example).

 

This problem doesn't seem to apply with a public CA so I am assuming something is in place to fix this automatically? If so can I apply this to our Windows CA please?

 

Thanks

Posted (edited)

There's a checkbox to add the DNS name as part of the SAN in the certificate template properties (subject tab) but it only looks like it works when the info is retrieved from info in AD.

 

Have a look here as well, but just be aware that the web pages here need to have ADCS web enrollment enabled: https://www.vkernel.ro/blog/configure-internal-windows-ca-to-issue-san-certificates

 

Edit - just noticed that a few of the commands have escaped HTML in them so remove the & and replace with the ampersand character

Edited by computer_expert
Posted
I have been doing that but sometimes it’s nice to use the CSR already provided. Also some applications are really fussy! Unifi seems to have issues if you don’t use a certificate provided by their CSR.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...