Win2003 PKI : Subordinate CA certificate parameter
I have installed two Win2003 Standard edition servers. I use one as a standalone root CA. The second is a standalone (no enterprise) subordinate CA. In the root CA I can succesfully change the CApolicy.inf file to make the Root CA certificate keyusage field 'critical' and have the following value: 'Certificate Signing, Off-line CRL Signing, CRL Signing (06)' I want to achieve the same for the Subordinate CA, but the same parameters I used for the Root don't work in the Sub. CApolicy.inf file. Or in any other policy.inf file for that matter.
ex.
[Extensions]
;The Extensions section marks the KeyUsage as critical
2.5.29.15=AwIBBg==
Critical=2.5.29.15
Can anyone help?
Thanks
Kris
Re: Win2003 PKI : Subordinate CA certificate parameter
Try to run the following command before you issue the subordinate certificate -- certutil -setreg policy\EditFlags -EDITF_ADDOLDKEYUSAGE and see what results you get. I will recommend you go through some documentation based on this. There are ample of resources available on web.
Re: Win2003 PKI : certreq.exe using 'special' subject fields
I had provided a link that refer a number of different articles to configure Windows Server. I am sure that will be helpful and will offer you detailed description on what you are looking for. It is necessary that you check the settings properly. There might be some small fix available. Try to work with default settings.
Windows Server 2003
Customize Key usage on subordinate CA
I apologize for being rude. I can't see much clear online documentation on this issue. The problem is exactly the same reported by Kris: I need to customize the setup of a subordinate CA so that its certificate has a Key Usage value of only 'Certificate Signing, Off-line CRL Signing, CRL Signing (06)'. I successfully setup the Root CA editing the CAPolicy.inf file with the lines :
[Extensions]
2.5.29.15=AwIBBg==
Critical=2.5.29.15
But the setup of the subordinate CA seems even more tricky. I used the setreg command you mentioned (certutil -setreg policy\EditFlags -EDITF_ADDOLDKEYUSAGE) on the Root CA before issuing the certificate, but the request (just as in the case of Kris) reads "Key Usage (Digital Signature,...)" and the CA root did not issue the certificate I want. I certainly miss something, but what ? Technet (http://technet2.microsoft.com/window....mspx?mfr=true) did not say much more. PLease help.
Both CAs are Windows 2003.
Re: Win2003 PKI : Subordinate CA certificate parameter
Just to be sure, you want to have the key usage on a subordinate ca defined only for Certificate Signing, Off-line CRL Signing, CRL Signing - 0x06. And you have edited the Root CA CAPolicy.inf? I think that this is the issue. You need to edit the subordinate CA's CAPolicy.inf as this is the place where you specify what kind of information will be present in the request for a certificate. You can verify if your's subordinate CA's certificate request contains the right key usage using certutil -dump request.req commmand.
Re: Win2003 PKI : Subordinate CA certificate parameter
You have to work with CAPolicy.inf here. It is located on the subordinate CA. This inf is used for the enrollment process and I am sure it is going to help you. The content of this files basically depends on the file. You can use to customize the parameter and use them before CA installation.
Re: Win2003 PKI : Subordinate CA certificate parameter
Dear all,
I have a problem with PathLenConstraint value,
My subordinate CA has already setup, but when i check its certificate, the PathLenConstraint value is none, so how can i change it to zero or some thing different.
Thanks,