Monthly Archives: May 2011

How to issue EV SSL certificates from an Enterprise CA

A question that I get all the time, is how to issue internal Extended Validation certificates from an internal Enterprise CA. Even though EV certificates do not provide increased security from a technical point of view, sometimes people just want … Continue reading

Posted in PKI | Tagged , | 3 Comments

Do not enable SAN certificate requests on your Enterprise CA’s!

Not many people are not aware of the fact that enabling SAN attributes in certificate requests can be a security issue. I have seen many people on different forums that tell other people to enable EDITF_ATTRIBUTESUBJECTALTNAME2 with certutil on Enterprise … Continue reading

Posted in PKI | Tagged , | Leave a comment