Home » Categories » Multiple Categories

SSL Certificate does not validate properly

Issue:

The SSL certificate won't validate properly because the certificate didn't include any subject alternative names. Adding SAN (Subject Alternative Name” into “Additional Attributes” field on a Microsoft Certificate Authority certificate request form does not generate a certificate with a SAN entry.

Solution:

Solution 1

Please review the this article that describes the problem and solution. Essentially, you must run a script to correct the issue that the issuance policy of the Microsoft CA is not configured to accept the Subject Alternative Name(s) attribute via the CA Web enrollment page.

Then, when using the web certsrv, add this under the attributes:

san:dns=your.fqdn.xxx

Solution 2

Another possible solution is to pass the config file below (include your information) to openssl.

[ req ]
default_bits = 2048
prompt = no
distinguished_name = req_distinguished_name
req_extensions = req_ext
[ req_distinguished_name ]
countryName = US
stateOrProvinceName = XXXX
localityName = XXXX
organizationName = XXXXXXX
commonName = your.fqdn.com
[ req_ext ]
subjectAltName = @alt_names
[ alt_names ]
DNS.1 = your.fqdn.com

Then, this when doing the CSR (Certificate Signing Request):

openssl req -new -key nagiosxi.key -out nagiosxi.csr -config thefile
0 (0)
Article Rating (No Votes)
Rate this article
  • Icon PDFExport to PDF
  • Icon MS-WordExport to MS Word
Attachments Attachments
There are no attachments for this article.
Related Articles RSS Feed
Pages Not Displaying Correctly
Viewed 3790 times since Mon, Jan 25, 2016
Nagios XI - How To Delete A Data Source From An RRD File
Viewed 7059 times since Wed, Apr 27, 2016
Nagios XI - Unable to Delete Host
Viewed 9272 times since Tue, Dec 16, 2014
OpenSSL causes issue with check_nrpe plugin with NSClient++
Viewed 937 times since Fri, Apr 30, 2021
Nagios XI - Performance Graph Problems
Viewed 16724 times since Fri, Dec 19, 2014
Backups are not being generated due to tar creation errors
Viewed 1630 times since Thu, Feb 27, 2020
Nagios Core - Nagios did not exit in a timely manner
Viewed 3756 times since Wed, Jan 27, 2016
Nagios XI - Configuration Applies, but still get "Configuration File Is Out Of Date" Error
Viewed 2504 times since Tue, Jan 26, 2016
Nagios XI - Notifications Not Sending In XI 5.3.0
Viewed 2643 times since Tue, Oct 4, 2016
Nagios XI - Bandwidth Graphs Showing 0Mb/s in Non-English Systems
Viewed 3733 times since Fri, Dec 19, 2014