Hi I've followed the below confluence doc for this setup. But need to resolve an issue regarding an SAN (Subject Alternative Name missing) insecure error which constantly pops up via chrome? & other browsers when local users go to our local secured intranet now eg. HTTPS://TCG Intranet,,,etc
Is there a way to add a SAN entry to the cert? I've done a ton of searching....
I used keytool successfully below article was helpful to a point:
https://stackoverflow.com/questions/30755220/how-to-create-csr-with-sans-using-keytool
Sorted. The below works, alternatively you could recreate the selfsigncert on you domain controller cert server but add the addtional 'subjective alternate name' entries ( which is the same as the cn entry plus any other dns name's associated to the same ip) then convert the pfx file to a keystore type....etc:
Here are my instructions using the KeyStore Explorer tool.
The 2 things I was previously missing when I created the cert were:
Without those 2 things Chrome will issue warnings / errors even when you have installed the self-signed certificate into your MS-CAPI PKI Trust store (as a "Trusted Root Authority).
Here are the steps I used.
It is pity thay you do not provide the commands to run with it, it looks very hard way to implement. is there no shorten way than 38 steps?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.