THIS KNOWLEDGE BASE HAS BEEN ARCHIVED AND IS NO LONGER BEING UPDATED
Please visit library.nagios.com/docs for the latest and most up-to-date documentation.
Home » Categories » Multiple Categories

SSL Certificate does not validate properly

Issue:

The SSL certificate won't validate properly because the certificate didn't include any subject alternative names. Adding SAN (Subject Alternative Name” into “Additional Attributes” field on a Microsoft Certificate Authority certificate request form does not generate a certificate with a SAN entry.

Solution:

Solution 1

Please review the this article that describes the problem and solution. Essentially, you must run a script to correct the issue that the issuance policy of the Microsoft CA is not configured to accept the Subject Alternative Name(s) attribute via the CA Web enrollment page.

Then, when using the web certsrv, add this under the attributes:

san:dns=your.fqdn.xxx

Solution 2

Another possible solution is to pass the config file below (include your information) to openssl.

[ req ]
default_bits = 2048
prompt = no
distinguished_name = req_distinguished_name
req_extensions = req_ext
[ req_distinguished_name ]
countryName = US
stateOrProvinceName = XXXX
localityName = XXXX
organizationName = XXXXXXX
commonName = your.fqdn.com
[ req_ext ]
subjectAltName = @alt_names
[ alt_names ]
DNS.1 = your.fqdn.com

Then, this when doing the CSR (Certificate Signing Request):

openssl req -new -key nagiosxi.key -out nagiosxi.csr -config thefile


Special Offer For Knowledgebase Visitors! Get a huge discount on Nagios Log Server by clicking below.

Get 60% Off Nagios Log Server!

Did you know? Nagios provides complete monitoring of: Windows, Linux, UNIX, Servers, Websites, SNMP, DHCP, DNS, Email, Storage, Files, Apache, IIS, EC2, and more!

1 (2)
Article Rating (2 Votes)
Rate this article
  • Icon PDFExport to PDF
  • Icon MS-WordExport to MS Word
Attachments Attachments
There are no attachments for this article.
Related Articles RSS Feed
Enabling Oracle Linux Optional Repository
Viewed 21440 times since Mon, May 14, 2018
Nagios XI - How To Test Check Commands From The Command-line
Viewed 55043 times since Tue, Jan 26, 2016
Nagios XI - Event Data Is Stale
Viewed 7310 times since Wed, Jan 27, 2016
API changes in Nagios XI 5.7
Viewed 5385 times since Tue, Feb 23, 2021
ERROR: Please add the ’Optional’ channel to your Red Hat systems subscriptions
Viewed 30010 times since Tue, Jan 26, 2016
Nagios XI - STRICT_TRANS_TABLES
Viewed 10872 times since Thu, Nov 16, 2017
Nagios XI - Status Information Cut Off At 256 Characters
Viewed 9823 times since Thu, Feb 25, 2016
Nagios XI - Can’t Log Into The Web Interface
Viewed 68183 times since Tue, Jan 27, 2015
Nagios XI - WMI Authentication Problems
Viewed 7614 times since Thu, Feb 25, 2016
Pages Not Displaying Correctly
Viewed 10210 times since Mon, Jan 25, 2016