Home » Categories » Multiple Categories

SSL Certificate does not validate properly

Issue:

The SSL certificate won't validate properly because the certificate didn't include any subject alternative names. Adding SAN (Subject Alternative Name” into “Additional Attributes” field on a Microsoft Certificate Authority certificate request form does not generate a certificate with a SAN entry.

Solution:

Solution 1

Please review the this article that describes the problem and solution. Essentially, you must run a script to correct the issue that the issuance policy of the Microsoft CA is not configured to accept the Subject Alternative Name(s) attribute via the CA Web enrollment page.

Then, when using the web certsrv, add this under the attributes:

san:dns=your.fqdn.xxx

Solution 2

Another possible solution is to pass the config file below (include your information) to openssl.

[ req ]
default_bits = 2048
prompt = no
distinguished_name = req_distinguished_name
req_extensions = req_ext
[ req_distinguished_name ]
countryName = US
stateOrProvinceName = XXXX
localityName = XXXX
organizationName = XXXXXXX
commonName = your.fqdn.com
[ req_ext ]
subjectAltName = @alt_names
[ alt_names ]
DNS.1 = your.fqdn.com

Then, this when doing the CSR (Certificate Signing Request):

openssl req -new -key nagiosxi.key -out nagiosxi.csr -config thefile


Special Offer For Knowledgebase Visitors! Get a huge discount on Nagios Log Server by clicking below.

Get 60% Off Nagios Log Server!

Did you know? Nagios provides complete monitoring of: Windows, Linux, UNIX, Servers, Websites, SNMP, DHCP, DNS, Email, Storage, Files, Apache, IIS, EC2, and more!

0 (0)
Article Rating (No Votes)
Rate this article
  • Icon PDFExport to PDF
  • Icon MS-WordExport to MS Word
Attachments Attachments
There are no attachments for this article.
Related Articles RSS Feed
Nagios XI - Apply Configuration Fails - Backend login to the Core Configuration failed
Viewed 25686 times since Tue, Aug 2, 2016
Nagios XI - Modifying The Contents Of /usr/local/nagios/etc
Viewed 7204 times since Tue, Jan 26, 2016
Nagios XI - Last Check Time Not Updating
Viewed 20608 times since Tue, Jan 6, 2015
Nagios XI - Upgrade errors - root.crontab.orig: cannot overwrite existing file
Viewed 4726 times since Tue, Jan 26, 2016
Nagios XI - MRTG Reports SNMP_Session Errors
Viewed 5835 times since Wed, Jul 27, 2016
Disabling Outdated Versions of SSL/TLS
Viewed 8611 times since Thu, Aug 6, 2020
NDOUtils - Message Queue Exceeded
Viewed 16345 times since Thu, Jan 21, 2016
Installation errors on customized corporate builds of CentOS or RHEL
Viewed 13244 times since Tue, Jan 26, 2016
Nagios XI - Apply Configuration Never Completes
Viewed 22634 times since Tue, Jan 27, 2015
Performance Graphs Showing Data during Host Down Time Periods
Viewed 3121 times since Tue, Dec 7, 2021