Re: Validity period of certificates is not accepted anymore

From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 11/30/04


Date: Tue, 30 Nov 2004 05:33:07 -0800

you should be able to remove the "include symmetric algortihms" checkbox in
the template which will enable to CA to not require those extensions in the
request:

Windows Server 2003 certificate templates whitepaper:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03crtm.mspx

-- 
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
Top Whitepapers:
Auto-enrollment whitepaper: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
Best Practices for implementing Windows Server 2003 PKI: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx
Troubleshooting Certificate Status and Revocation whitepaper: 
http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
"Sebastian Rieger" <sebastian.rieger@gwdg.de> wrote in message 
news:%2343Hiav0EHA.2572@tk2msftngp13.phx.gbl...
> David Cross [MS] schrieb:
>> The CA policy module will always truncate the validity of an issued cert 
>> to be within the lifetime of its own validity period.  You must renew the 
>> CA with a longer lifetime to avoid this.
>>
>
> Thanks for your help! The feature of reducing the lifetime of a 
> certificate is great! I renewed the ca certificate though, to avoid having 
> users register their certificate a short time before the ca certificate 
> expires. I've got two valid CA certificates now (same key, different life 
> time) which seems to work fine even with the CRL etc.
>
> Thanks to you I now know that there seems to be no registry key or the 
> like, to avoid the life time from being cut down.
>
> I've got a new problem now, though! The life time of the certificate is 
> accepted (or shortened) by the policy module, but it states that there are 
> no SMIME capability extensions set. There used to be an extension for 
> this, but right now Netscape / Mozilla requests lack it.
>
> The policy modules rejects all requests of our users, complaining about
> the lacking extension (0x80094805 (-2146875387)). I couldn't find anything 
> in TechNet or on the Microsoft webpage.
>
> Strange thing is, requests sent in by an Internet Explorer are accepted by 
> the policy module. They ought to be constructed on the client side, using 
> Xenroll.dll, right? Selecting them from the pending request list, and 
> showing their extension works (the extensions contain the four encryption 
> types of SMIME capabilities, which are also set in defaultSMIME registry 
> key).
>
> Any help would (again) be greatly appreciated! Thanks again, for your 
> advice!
>
> Sebastian Rieger 


Relevant Pages

  • Re: certificate extension
    ... I have a problem in retaining the X509 extension in the end certificate ... openssl tool this what it looks like. ... I use "openssl ca" command to sign requests. ... A user "request" some extensions but the CA is the only authority who ...
    (comp.protocols.kerberos)
  • Re: OpenSSL
    ... | X.509v3 extension of the basic certificate. ... # X.509v3 extensions in its main section.) ... # the certificate can be used for anything *except* object signing. ... # Include email address in subject alt name: another PKIX recommendation ...
    (Fedora)
  • Re: Windows 2000 Certificate Services - Help Request (Understanding and operation).
    ... > produced as a result of requests from the subordinate server. ... > I have exported a certificate and imported it into Outlook 2002. ... > is capable of sending signed messages and recognising signed ...
    (microsoft.public.win2000.security)
  • Re: Certificate Authority
    ... a Windows .NET certificate authority. ... the self-signed root certificate is generated. ... So caution must be exercised before identifying critical extensions. ... as for subordinate installs and renewals. ...
    (microsoft.public.win2000.security)
  • Re: Cannot request computer certificate.
    ... Just to clarify, the cerutil - ping is working, not the certificate ... I am sure that the fact that the web requests work and the mmc ...
    (microsoft.public.windows.server.security)