Configuring Active Directory Certificate Services to support Subject Alternative Names

With the use of a single command, you can reconfigure Active Directory Certificate Services to support certificates with Subject Alternative Names (SAN).

Orin Thomas

June 27, 2010

1 Min Read
ITPro Today logo in a gray background | ITPro Today

With the use of a single command, you can reconfigure ActiveDirectory Certificate Services to support certificates with Subject AlternativeNames (SAN). Normally a certificate is tied to a single fully qualified domainname (FQDN). SANs allow SSL certificates to respond correctly to differentfully qualified domain names. This way you can have, for example, a singlecertificate handle requests for mail.contoso.com, owa.contoso.com,smtp.contoso.com and so on.

To configure Active Directory Certificate Services tosupport Subject Alternative Names, perform the following steps.

On a computer that has Active Directory Certificate Servicesinstalled, open an elevated command prompt and enter the command:

Certutil –setreg policyEditFlags+EDITF_ATTRIBUTESSUBJECTALTNAME2

Once you receive a message that the change has beensuccessfully implemented, restart AD CS. AD CS will now be able to issuecertificates that support Subject Alternative Names

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like