missing attributes and constraints are missing in CA generated certificate

Sajid Ali Shah 226 Reputation points
2022-11-16T12:34:59.237+00:00

Hi.

I received a CSR to generate a certificate from Local CA (Windows CA). the requester is saying this certificate needs to be a CA too, because it shall be used for SSL inspection.

can you guide me how can I generate certificate from Windows CA to have all the required attributes and constraints.

Regards

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,113 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,721 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2022-11-16T16:31:59.943+00:00

    Hello there,

    By installing the Certification Authority role service of Active Directory Certificate Services (AD CS), you can configure your Windows server to act as a CA.
    It would be best to determine how many CAs you will install and in what configuration before installing any CA.

    These instructions are applicable to a Microsoft Certification Authority deployed on Windows Server.

    Certification Authority Guidance https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh831574(v=ws.11)

    Constraints: what they are and how they’re used https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/constraints-what-they-are-and-how-they-amp-8217-re-used/ba-p/1129048

    ---------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–

    0 comments No comments