Article ID: 943089 - Last Review: February 6, 2009 - Revision: 3.0 A Windows Server 2003-based enterprise CA issues certificates that have incorrect alternate subject names and the certificates are not Network Access Protection (NAP)-compliantNoticeThe hotfix that is described in this Microsoft Knowledge Base article is superseded by the hotfix in KB961515. For more information about KB961515, click the following article number to view the article in the Microsoft Knowledge Base:961515
(http://support.microsoft.com/kb/961515/
)
The subject name of a computer certificate that is issued by a Windows Server 2003-based server is set to the user principal name (UPN) of the computer account after you apply hotfix 943089
On This PageSYMPTOMSConsider the following scenario:
This problem prevents the enterprise CA from issuing Network Access Protection (NAP)-compliant computer certificates. RESOLUTIONTo resolve this problem, apply hotfix 961515.
For more information about hotfix 961515, click the following article number to view the article in the Microsoft Knowledge Base:
961515
(http://support.microsoft.com/kb/961515/
)
The subject name of a computer certificate that is issued by a Windows Server 2003-based server is set to the user principal name (UPN) of the computer account after you apply hotfix 943089
Hotfix informationPrerequisitesTo apply this hotfix, you must have Windows Server 2003 Service Pack 1 or Windows Server 2003 Service Pack 2 installed on the computer. For more information, click the following article number to view the article in the Microsoft Knowledge Base:889100
(http://support.microsoft.com/kb/889100/
)
How to obtain the latest service pack for Windows Server 2003
Restart requirementYou must restart the computer after you apply this hotfix.Hotfix replacement informationThis hotfix is replaced by hotfix 961515.File informationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.Windows Server 2003 with Service Pack 1, x86-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, x86-based versionsCollapse this table
Windows Server 2003 with Service Pack 1, Itanium-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, Itanium-based versionsCollapse this table
Windows Server 2003, x64-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, x64-based versionsCollapse this table
This hotfix fixes an issue that occurs when the CT_FLAG_SUBJECT_ALT_REQUIRE_UPN flag is set in a computer template. When this flag is set, the policy module puts the DNS name of the computer in the Subject Alt Name (SAN) field. This is not the expected behavior. The following behavior occurs after you install the hotfix:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATIONNAP is a new platform that performs the following jobs:
https://www.microsoft.com/technet/network/nap/napoverview.mspx
(https://www.microsoft.com/technet/network/nap/napoverview.mspx)
For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684
(http://support.microsoft.com/kb/824684/
)
Description of the standard terminology that is used to describe Microsoft software updates
APPLIES TO
| Article Translations
|
Back to the top
