Configuring Active Directory Certificate Services to support Subject Alternative Names
With the use of a single command, you can reconfigure Active Directory Certificate Services to support certificates with Subject Alternative Names (SAN).
June 27, 2010
With the use of a single command, you can reconfigure ActiveDirectory Certificate Services to support certificates with Subject AlternativeNames (SAN). Normally a certificate is tied to a single fully qualified domainname (FQDN). SANs allow SSL certificates to respond correctly to differentfully qualified domain names. This way you can have, for example, a singlecertificate handle requests for mail.contoso.com, owa.contoso.com,smtp.contoso.com and so on.
To configure Active Directory Certificate Services tosupport Subject Alternative Names, perform the following steps.
On a computer that has Active Directory Certificate Servicesinstalled, open an elevated command prompt and enter the command:
Certutil –setreg policyEditFlags+EDITF_ATTRIBUTESSUBJECTALTNAME2
Once you receive a message that the change has beensuccessfully implemented, restart AD CS. AD CS will now be able to issuecertificates that support Subject Alternative Names
About the Author
You May Also Like