Friday, September 29, 2017

Adding SAN (Subject Alternative Name” into “Additional Attributes” field on a Microsoft Certificate Authority certificate request form does not generate a certificate with a SAN entry


You’ve completed the process of creating a new keystore with a CSR from the Portecle utility:


Since the Portecle utility does not provide the feature to include SAN entries:


This isn’t usually a problem because it is possible to add SAN entries in the Additional Attributes field when submitting the CSR to a Microsoft Certificate Authority server as described here:

How to add a subject alternative name to a secure LDAP certificate

An example of the format of the string to include is:

You proceed to submit the request:


… but notice that the generated certificate does not include a SAN entry.


One of the reasons why performing the above would not generate a certificate that includes a SAN entry is if the issuance policy of the Microsoft CA is not configured to accept the Subject Alternative Name(s) attribute via the CA Web enrollment page.  To correct this, execute the following command:

certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2


Once the above command is executed, stop and start the certificate authority with:

net stop certsvc
net start certsvc

Proceed to use the CA web enrollment page to generate the certificate with the SAN entry.


Security Concerns:

Note that as per the following Microsoft article:

It is not recommended to enable the acceptance of the SAN attribute for the CA Web enrollment page so please review the Security best practices for allowing SANs in certificates section in the article above to be aware of the security concerns.


Anonymous said...

Thanks for the fix!

Anonymous said...

this is like the first comment ever. never usually do this.
not this time.
thanks a lot, Terence!

Anonymous said...

Thanks! Been fighting this for hours!

Zuka said...

Thank you!

Simon R. said...

It's funny: I've done this at least 2 or 3 times in the past, and yet forgot about it. :)

But, a quick scan of your post had me going in no time. Thanks!