Unsolved

This post is more than 5 years old

1 Rookie

 • 

53 Posts

3535

January 29th, 2018 20:00

Generate CSR does not allow Subject Alternate Names

Hi There,

Under Application Settings > Security > Certificates, when attempting the generate a custom signing request, the wizard gives no option to for Subject Alternate Names (SAN) as part of the request, relying on Common Name (CN) in the subject.

Use of Common Name for Server Certificates has been deprecated from the standards from some time and Chrome will remove support for common name matching, and use of Sunbject Alternate Names (reference link).

Could OME Developers please look into updating the wizard to allow specification of SubjectAlternateNames, or give the ability to import a public *and* private key pair that we can generate outside of OME (e.g. pfx files, pem etc)

 

Thanks

4 Apprentice

 • 

2.8K Posts

January 30th, 2018 08:00

Hi bcshort and thanks for the post.

I checked with the team and it looks like this already under review as as roadmap item.

Thanks for calling it out.

Rob

1 Rookie

 • 

53 Posts

January 30th, 2018 19:00

Thanks Rob,

As an addendum, there also needs to be a way to upload intermediate/root certificates. When using an internal PKI, if you aren't able to upload Intermediate and Root CA Certificates, the OM Enterprise Server cannot verify the chain of trust for the certificate.

Cheers

Ben

4 Apprentice

 • 

2.8K Posts

January 31st, 2018 06:00

Ok, got it.  Added this to my information that I passed along for review.

Thanks!

Rob

1 Rookie

 • 

5 Posts

October 31st, 2018 07:00

Hello Is there any update related to the certificate update process on DellEMC Open Manage Enterprise? I cannot upload certificates which have all the components (key, config file, csr, cert) generated outside the DellEMC OME. The CA is external and completely managed offside. Thanks ikroumov

0 events found

No Events found!

Top