After applying build 522 the validity period and extensions included in certificates issued via AEP Proxy are NOT as expected
Originally Published: 2013-08-19
Article Number
Applies To
Fedora Auto Enrollment Proxy (AEP)
Microsoft Windows Server 2003
Issue
aep.xuda
Cause
Resolution
Also inspect differences in the following files and update those as well if required:
RSA_CM/WebServer/admin-server/ca/aep/aep-auto-add-request.xuda
RSA_CM/WebServer/admin-server/ca/aep/aep-renew-certificate.xuda
Workaround
Notes
[@useAD='1']
In build 517 (or previous to build 520), when requesting certificates through AEP, the subject of issued cert was taken from Active Directory. In build 520 (and later), the subject DN can be taken from PKCS#10 request. Set useAD flag to 1 (in build 520 or later) to keep the old behavior (use subject DN from AD). Set useAD flag to 0 (in build 520 or later) to use subject DN from PKCS#10. The default behavior remains un changed in newer builds.
An issue around TTL was fixed in build 519. See the following solution for more details:
When issuing a cert via AEP the validity period is always set to 1 year no matter the validity specified in the extension profile/Jurisdiction.
The following new parameter was added to aep-auto-add-request.xuda in build 520 (and also shows up in later builds):
NO_TTL
If NO_TTL flag is set, the value set for directive TTL is ignored and the validity period is taken from jurisdiction configuration when requesting certificates through AEP.
Related Articles
When issuing a cert via AEP the validity period is always set to 1 year no matter the validity specified in the extensio… 7Number of Views How to Export Active Directory Root Certificate to Enable SSL for RSA SecurID Cloud Authentication Service Idenity Source 48Number of Views Choosing a Connection Method to Add an SSO Agent Application 36Number of Views New PIN Mode and Next Tokencode Mode not working from the web pages using RSA Authentication Agent for Web for Apache on R… 73Number of Views How to fix Account Collector for Active Directory when it fails with java.lang.NoClassDefFoundError in RSA Via Lifcycle an… 215Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update
Don't see what you're looking for?