Using Custom Policy Module SubjectAltName
HiI don't know if anybody has already used this custom policy module with ILM but I can't make it work at the moment.I've configured my CA by adding the "SubjectAltName Module 1.1" and configuring a DNS name in theextension by mentionning {CLM!dataItem1} corresponding to my datacollection item of my profile template.Then I've configured my profile template by adding a data collection (Type: string, Information provided by: Certificate manager, Validation Type: Data Type, Stored data in: Extension) then an edit box has appeared and I don't know what to enter here !!!SO now when I look the content of my certificate, I can see a subjectaltname but the value is DNS={CLM!dataItem1} !!Is there an explanation ?Thks
October 1st, 2009 7:01pm

Hi Anthony,First of all, the name of your data collection will need to match what you've entered in the custom policy module's configuration, i.e. dataItem1.Secondly, you should be storing the dataitemin the database; that is where the custom policy module retrieves the data collection value you've defined. By selecting to store the data in an Extension, you're beingprompted to specify what certificate extension to will contain the value, and I believe that subsequently, when the data collection value is submitted, it'sbaked into the certificate request.Try changing where you store the data collection value to the database and ensure the data item is the same in the profile template policy configuration and the custom policy module configuration. After those changes, try enrolling for another certificate and see if the subjectAltName is correct.Cheers,Marc Marc Mac Donell, ILM MVP, Senior Consultant (Identity Assurance), Avaleris Inc.
Free Windows Admin Tool Kit Click here and download it now
October 1st, 2009 8:23pm

In addition to Marc's comments can you provide a little more detail about what you're trying to do here? I assume that these are computer certificates, but do the computers in question have Active Directory accounts? I'm just curious as to what the workflow looks like here, and a better understanding of what you're trying to accomplish may allow us to offer you some better alternatives.Paul Adare CTO IdentIT Inc. ILM MVP
October 1st, 2009 8:57pm

This is a known issue; youcannotuse the "Stored in Extension". Have to be Stored in Database.BrjannThis posting is provided "AS IS" with no warranties, and confers no rights
Free Windows Admin Tool Kit Click here and download it now
October 2nd, 2009 2:09am

Hi allI found the problem, you must type Clm and not CLM if you want to use the custom policy module so I've replaced {CLM!dataItem1} by {Clm!dataItem1}thks for your help everybodyAnthony
October 2nd, 2009 3:29pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics