RE: Generate CSR for web srv cert with email address via IIS5?

From: Mike Lagase [MS] (mikelag@online.microsoft.com)
Date: 11/11/02


From: mikelag@online.microsoft.com (Mike Lagase [MS])
Date: Mon, 11 Nov 2002 20:44:08 GMT


If you have a Microsoft Enterprise Root CA installed in your Active
Directory domain, then when you request a certificate from this CA. In the
new certificate, the Subject Alternative Name will have your Principal Name
embedded in the certificate. This is your UPN logon in the Active
Directory. This will allow implicit logons using client certificates in
your AD without the need for adding a Name mapping in the Active Directory.

More information on this UPN mapping can be found at
http://www.microsoft.com/windows2000/techinfo/planning/security/mappingcerts
.asp

Hope this helps.

Mike Lagase
Microsoft Internet Server Support.



Relevant Pages

  • Re: Computer and User Certificates Issues
    ... Enrollment of User Certificates using the custom v2 User Certificate Template ... I can NOT request the custom v2 Computer Cert nor the included v1 no ... Concerning permissions, these are the exact permissions I am using now: ...
    (microsoft.public.security)
  • Re: Cannot request computer certificate.
    ... request a computer certificate for about 9 months. ... and verify that you can get a computer/server certificate from it. ... List of NetBt transports currently bound to the Redir ... DNS Host Name: srvr3.domain.com ...
    (microsoft.public.windows.server.security)
  • RE: SIMple SSL question ??
    ... OK - i would also delete a cert request file lying around. ... But a certificate is a pub key + extra info. ... That said - if someone compromises the server he will also find a way to retrieve the private key. ... traffic between the initial web server and the client. ...
    (microsoft.public.dotnet.security)
  • Re: how can we restrict what certificate WSE will use?
    ... the valid x509 certificate which is used to identify him'. ... X509SecurityTokenManager to verify the request is from a trusted client. ... the problem is that he can not passed the authentication (suppose we ... > decrypte and signature validation process. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Web Certificate Enrollment security problem
    ... Enrollment works only with the NetBIOS Name and not with the FQDN. ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... access auditing and logging "issue and manage certificate requests" on ... Have seen that there is a component "Certsrv Request" when launching ...
    (microsoft.public.security)