Certificate Management Protocol (CMP) request values are being overridden by KCA jurisdiction settings
Originally Published: 2004-03-16
Article Number
Applies To
Microsoft Windows 2000 Server
Issue
RDN values in the Certificate Management Protocol (CMP) certificate request are ignored
V3 extension requests in the Certificate Management Protocol (CMP) certificate request are ignored
Cause
Resolution
1. If you do not wish the DN and extension profile to be enforced, uncheck the checkboxes from the Jurisdiction configuration.
2. Create a customer extension profile and add the Subject Alternative Name extension to the Basic PKIX EE extension profile (note that issued certificates will also contain the other extensions in this profile). Also, add the OU attribute to the required attributes in the Jurisdiction configuration.
3. If you do not want to change this Jurisdiction configuration because it is required for other (non-CMP) certificates, create a new Jurisdiction with the desired configuration for CMP requests (a CA may have multiple Jurisdictions).
Workaround
Related Articles
Delete unwanted Certificate Signing Requests (CSR) from the RSA Authentication Manager Operations Console Certificate Mana… 2.54KNumber of Views Using an IP address override to fix an initial authentication failures with RSA Authentication Manager when the error Auth… 1.03KNumber of Views ERR_SSL_PROTOCOL_ERROR when accessing RSA Authentication Manager Security and Operations Consoles with Google Chrome 117 a… 1.1KNumber of Views How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. 760Number of Views Signed Certificate Management Protocol (CMP) requests do not work in KCA 6.5.1 if certificate's DN contains 'special' char… 3Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?