Quantcast
Channel: Distro Discussion & Help - FreePBX Community Forums
Viewing all articles
Browse latest Browse all 1370

Generated Certificate requests not working post-fulfillment

$
0
0

I’m using a Microsoft CA, so right off I’m stuck generating the certificate with no “template” as required by MS. I was able to manipulate the authority into supplying a “Web Server” template during generation, but had to use the CLI instead of the gui tools. More of an MS problem if you ask me, but solvable.

My problem is that my browser doesn’t like the certificates that are generated, complaining about a missing “Subject Alternative Name (SAN)”. Apparently modern browsers only accept certs with a SAN, even if the common name matches. Edge states:

“This server couldn’t prove that it’s pbx.domain.local; its security certificate does not specify Subject Alternative Names. This may be caused by a misconfiguration or an attacker intercepting your connection.”

How can I get the SAN submitted with my cert? I’d like to submit something like an IP address as well. I know I could just issue the request with openssl, but then what good is this part of the module?

I have an active sysadmin pro module subscription on most if not all systems I manage.

10 posts - 3 participants

Read full topic


Viewing all articles
Browse latest Browse all 1370

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>