[Pki-users] SAN:howt is it possible to sign certificate requests with DNS alias names?

Supper Florian OSS sIT Florian.Supper at s-itsolutions.at
Wed Dec 9 07:19:54 UTC 2015


Hi,

here the section in my profile.
With this extionsion, you can easily put the SAN Names in your certificate request.

policyset.webprofile.10.constraint.class_id=noConstraintImpl
policyset. webprofile.10.constraint.name=No Constraint
policyset. webprofile.10.constraint.subjAltNameExtCritical=false
policyset. webprofile.10.default.class_id=userExtensionDefaultImpl
policyset. webprofile.10.default.name=User Supplied Extension Default
policyset. webprofile.10.default.params.userExtOID=2.5.29.17

Br
Florian

-----Ursprüngliche Nachricht-----
Von: pki-users-bounces at redhat.com [mailto:pki-users-bounces at redhat.com] Im Auftrag von Carsten Grzemba
Gesendet: Mittwoch, 09. Dezember 2015 08:08
An: Pki-users at redhat.com
Betreff: [Pki-users] SAN:howt is it possible to sign certificate requests with DNS alias names? [phishing][bayes][heur][html-removed]

I try to sign certificate requests with SAN extension to have DNS alias names, but with no success. I see that there are subjectAltNameExt in the profile but my 

policyset.serverCertSet.9.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$

is always null, although I have

input.i3.name=subjectAltNameExtInputImpl

for the inputs.
What I am doing wrong?
_______________________________________________
Pki-users mailing list
Pki-users at redhat.com
https://www.redhat.com/mailman/listinfo/pki-users




More information about the Pki-users mailing list