Unrecognized string/value shown in SubjectAltName extension of a certificate issued using the MS Logon Cert profile
2 years ago
Originally Published: 2002-01-03
Article Number
000058371
Applies To
Keon Certificate Authority
KCA 6.0.1
Microsoft Windows NT 4.0
Microsoft Windows 2000
Microsoft Internet Explorer 5.5
TM 6113
Issue
Unrecognized string/value shown in SubjectAltName extension of a certificate issued using the MS Logon Cert profile
Downloading a client certificate (issued as MS Logon Cert) to MSIE on Windows NT shows incorrect value for the Subject Alternative Name v3 extension, like:

 "Other Name=No alternative name"

It doesn't occur on Windows 2000.  The same certificate shows the value correctly as:

"Other Name:
    Principal Name=any@rsasecurity.com"
Resolution
This happens only on Windows NT.  On Windows 2000, this problem does not appear.  This is not a bug or a problem because MS Logon Cert based certificates are not supported on Windows NT, they are meant for Windows 2000.