New template - can't pass SAN
Odd situation. Yes, it's not ideal. :-) My domain controllers are running Windows 2008 SP2 STANDARD.One of my DCs had the Certificate Authority feature installed on it.To get something going, in a pinch, I built a new 2008 R2 ENTERPRISE server and installed the CA feature as an additional root CA.I was able to create a new web server template to have both Server Authentication and Client Authentication policies enabled in the template.From the host machine I went to http://server/certsrv and submitted a new request by pasting in the CSR.As part of the submission, I passed in san:dns=fqdn1&dns=fqdn2. After the above, the cert was issued. I thought nice. I figured I would keep the new Ent CA. As certs came up for expiration on the 2008 Standard CA, I could eventually cut them over to the new Ent CA and in time, I could decommission the old CA. Unfortunately, when I check the newly issued cert, the subject alternate names do not appear in the cert. I can't figure out how, why not. The template was configured such that the Subject Name tab has the "Supply in the request" radio button selected. What am I doing wrong? (Other than the fact that I have a funky 2 root CA setup in the same forest/domain). By the way, I have a single forest/domain model. Thanks...
May 8th, 2012 3:05pm

Yo....... Thank you!
Free Windows Admin Tool Kit Click here and download it now
May 8th, 2012 3:34pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics