AD CS (PKI) – how to configure SAN (subject alternative names)
If you want to use Subject Alternative Names on internal SSL certificates issued by Active Directory Certificate Services you have to configure CA (Certificate Authority) to accept SAN attribute from a...
View ArticleAD CS 2008 R2 Two-tier Install Procedure
2013: Test Lab Guide: Deploying an AD CS Two-Tier PKI Hierarchy : http://technet.microsoft.com/en-us/library/hh831348.aspx Certificate Services Concepts:...
View ArticleAD CS (PKI) Resources (and Migration to 2012 R2)
Here are resources and comments about ADCS migration to 2012 R2: https://windorks.wordpress.com/2014/08/12/migrating-a-microsoft-pki/...
View ArticleAD CS (PKI) Choosing a Hash and Encryption Algorithm for a new PKI?
Reference: http://blogs.technet.com/b/askpfeplat/archive/2013/04/22/choosing-a-hash-and-encryption-algorithm-for-a-new-pki.aspx ” If you absolutely must support legacy applications that don’t...
View ArticleAD CS (PKI) – Multiple PKI on a same forest?
Is it possible to cohabit with an old PKI hierarchy and a new PKI in a same Forest? “Yes you can have multiple root CAs and even multiple PKIs in a single Active Directory forest. Because of the way...
View ArticlePKI – Certificates – Troubleshooting certificate enrollment RPC server is...
Web references: http://www.networksteve.com/forum/topic.php/CCertRequest::Submit:_The_RPC_server_is_unavailable._0x800706ba/?TopicId=54320&Posts=3...
View ArticlePKI – Certificates – Certutil -restrict or how to dump CA database
Certutil view restrict description: http://blogs.technet.com/b/pki/archive/2008/10/03/disposition-values-for-certutil-view-restrict-and-some-creative-samples.aspx Disposition values for requests in the...
View Article