MS PKI: Special Subject Fields in certificate Request

MS PKI: Special Subject Fields in certificate Request

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
MS PKI: Special Subject Fields in certificate Request Kris 09-24-2007
Posted by Kris on September 24, 2007, 6:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options

I have the following problem:
I use win2003 Server Standard ed. with MS Certificate services.

Using certreq.exe I can successfully generate a certificate request
that looks like this:

-*Subject*:
E=email@email.com
CN=Some CN
OU=Org Unit
T=Mega Title
SN=123456
O=Org.
C=BE-

But when I have this certificate signed by a WIN2003 Server St Ed.
Certificate Server sub CA. The resulting certificate does not have the
"SN=123456" field anymore included in the certificate. For some reason
the CA has deleted this field from the subject. No errors occured
during the Issuing in the CA mmc tool.

Any idea's why? Does MS only allow certain subject fields. Any
debugging possibilities?

I am also looking into how I could add an not so useal field to this
subject in the request and have it signed. ex:

-*Subject*:
E=email@email.com
CN=Some CN
OU=Org Unit
T=Mega Title
OID.2.5.4.5=123456
O=Org.
C=BE-

CERTUTIL -V -DUMP ...
-*Details*:
[4,0]:
CERT_RDN_PRINTABLE_STRING, Length = 10 (10/1024 Characters)
2.5.4.5 Serial Number="123456"

50 4e 3a 20 33 30 30 30 30 39 123456
50 00 4e 00 3a 00 20 00 33 00
30 00 30 00 30 00 30 00 39 00
1.2.3.4.5.6.-

Anybody any idea how I need to use certreq.exe and the policy.inf file
to get to such a solution? Or if this is possible at all?

Thanks
Kris


--
Kris
------------------------------------------------------------------------
Kris's Profile: http://forums.techarena.in/member.php?userid=30895
View this thread: http://forums.techarena.in/showthread.php?t=823023

http://forums.techarena.in


Similar ThreadsPosted
Error parsing Request: The request subject name is invalid or too long. 0x80094001 (-2146877439) February 27, 2007, 4:01 am
Subject Alternate Name Certificate Native Suport April 17, 2008, 10:31 am
Cannot Request Certificate February 27, 2007, 7:45 am
LDAPS--certificate request February 3, 2006, 12:44 pm
Certificate Request Question March 3, 2006, 10:31 am
Certificate request only 2 years December 5, 2007, 9:59 am
Permissions requried to request a certificate. September 8, 2008, 9:07 pm
Automatic Certificate Request Setup Wizard May 24, 2006, 4:41 am
How to request client certificate, non domain computers December 5, 2007, 9:39 am
Certificate Enrollment API: Request on behalf of another user February 13, 2008, 9:02 pm

The site map in XML format XML site map

Contact Us | Privacy Policy