autoenrolling a cert for WinRM with both for hostname and fqdn

Myrvin Fernandez 1 Reputation point
2021-01-12T21:00:53.66+00:00

Hi All,

Whenever I connect to Winrm over https it only works via FQDN because the ssl cert subject or subject alternative name only has the FQDN.

Has anyone successfully been able to autoenroll with both shortname and FQDN in the cert. The cert template does not provide an option for shortname AFAIK.

Looks like a common issue but I doubt leaving the subject name as blank is the answer given in spiceworks:

https://social.technet.microsoft.com/Forums/lync/en-US/c62184fb-7924-4fe5-ab7f-6c48f78f6819/certificate-template-subject-name-built-from-ad?forum=winserversecurity

https://serverfault.com/questions/361128/automatically-create-subject-alternate-name-san-certificates

https://community.spiceworks.com/topic/2095596-netbios-name-on-ssl-certificate-generated-by-ad-certificate-services

Thanks

Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
421 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,730 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,383 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2021-01-12T22:36:32.853+00:00

    Hi,

    If in the SAN value in the certificate you have only one FQDN , you can connect to this server only with this FQDN to use Winrm over https. Because the certificate accept only once name mentioned in the SAN. It is the limitation when you choose to use auto enrollment to generate a server certificat.

    If you want use another name , you have to create new computer or server certificate template in order to generate manually new certificate with the list of all server FQDN in the SAN Subject alternative Name.

    The link below can help you to set the new template:

    web-server-certificate-enrollment-with-san-extension.aspx


    Please don't forget to mark helpful reply as answer


  2. Vicky Wang 2,646 Reputation points
    2021-01-21T08:41:58.283+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments

  3. Vicky Wang 2,646 Reputation points
    2021-01-25T08:49:01.373+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments

  4. Vicky Wang 2,646 Reputation points
    2021-01-27T09:28:39.603+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments