System TipThis article applies to a different operating system than the one you are using. Article content that may not be relevant to you is disabled.
Windows Server 2008 handles the certificate mapping by using the common name (CN) of the "Issuer" field of a certificate. This behavior is by design and could not be changed by a user.
This hotfix introduces a new feature for Windows Server 2008. The new feature enables Windows Server 2008 to handle the certificate mapping by using the CN of only the "Subject" field. The new feature is added in the authentication module in Windows Server 2008.
You must install this hotfix on all domain controllers. After you install this hotfix, you must follow these steps on one of the domain controllers to enable this feature for one or more users:
On the domain controller, open the "Active Directory Users and Computers" snap-in.
In the "Active Directory Users and Computers" window, click Advanced Features on the View menu.
Expand DomainName, and then click Users. Note DomainName represents the fully qualified domain name (FQDN) of the domain.
Double-click a user to enable this feature for that user.
In the Properties dialog box, click the Attribute Editor tab.
On the Attribute Editor tab, double-click the altSecurityIdentities attribute.
In the Multi-valued String Editor dialog box, type the following value under Value to add, and then click Add:
X509N:<S>CN=CertificateSubjectName Note CertificateSubjectName represents the CN of the "Subject" field of the user certificate.
Click OK two times.
Repeat step 4 through step 8 as required if you want to enable this feature for other users.
Important Windows Vista and Windows Server 2008 hotfixes are included in the same packages. However, only one of these products may be listed on the “Hotfix Request” page. To request the hotfix package that applies to both Windows Vista and Windows Server 2008, just select the product that is listed on the page.
The global version of this hotfix has the file attributes (or later file attributes) that are listed in the following table.
Windows Server 2008 file information note
The files that apply to a specific product, SR_Level (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.
Collapse this tableExpand this table
Version
Product
SR_Level
Service branch
6.0.600
1
.
18xxx
Windows Server 2008
SP1
GDR
6.0.600
1
.
22xxx
Windows Server 2008
SP1
LDR
6.0.600
2
.
18xxx
Windows Server 2008
SP2
GDR
6.0.600
2
.
22xxx
Windows Server 2008
SP2
LDR
Service Pack 1 is integrated into the original release of Windows Server 2008.
The MANIFEST files (.manifest) and the MUM files (.mum) that are installed for each environment are
listed separately. MUM and MANIFEST files, and the associated security catalog (.cat) files, are critical to maintaining the state of the updated component. The security catalog files (attributes not listed) are signed with a Microsoft digital signature.
The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
For all supported x86-based versions of Windows Server 2008
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
Kdcsvc.dll
6.0.6001.22498
312,832
17-Aug-2009
12:29
x86
Kdcsvc.mof
Not applicable
5,300
01-Apr-2009
19:14
Not applicable
Kdcsvc.dll
6.0.6002.22201
312,832
17-Aug-2009
11:59
x86
Kdcsvc.mof
Not applicable
5,300
03-Apr-2009
21:47
Not applicable
Kerberos.dll
6.0.6001.22498
500,224
17-Aug-2009
12:29
x86
Kerberos.dll
6.0.6002.22201
500,736
17-Aug-2009
11:59
x86
Schannel.dll
6.0.6001.22498
271,360
17-Aug-2009
12:31
x86
Schannel.dll
6.0.6002.22201
271,872
17-Aug-2009
12:01
x86
For all supported x64-based versions of Windows Server 2008
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
Kdcsvc.dll
6.0.6001.22498
406,016
17-Aug-2009
12:13
x64
Kdcsvc.mof
Not applicable
5,300
01-Apr-2009
16:43
Not applicable
Kdcsvc.dll
6.0.6002.22201
406,016
17-Aug-2009
12:19
x64
Kdcsvc.mof
Not applicable
5,300
03-Apr-2009
21:07
Not applicable
Kerberos.dll
6.0.6001.22498
658,944
17-Aug-2009
12:13
x64
Kerberos.dll
6.0.6002.22201
658,944
17-Aug-2009
12:19
x64
Schannel.dll
6.0.6001.22498
339,456
17-Aug-2009
12:15
x64
Schannel.dll
6.0.6002.22201
338,944
17-Aug-2009
12:21
x64
Kerberos.dll
6.0.6001.22498
500,224
17-Aug-2009
12:29
x86
Kerberos.dll
6.0.6002.22201
500,736
17-Aug-2009
11:59
x86
Schannel.dll
6.0.6001.22498
271,360
17-Aug-2009
12:31
x86
Schannel.dll
6.0.6002.22201
271,872
17-Aug-2009
12:01
x86
For all supported Itanium-based versions of Windows Server 2008