PKI custom SAN extensions and SubjectAltNameExtDefault gname is empty during CA configuration
Issue
Before configuring a Red Hat Certificate System CA, with either with pkisilent or manually with the web based configuration wizard, it is possible to set custom extensions for certificates, by modifying template files.
For example, the CA's SSL server certificate, in either files below, for all subsequent CA created with the pkicreate command:
/usr/share/pki/ca/conf/serverCert.profile
or for just an already created with the command pkicreate, but unconfigured CA instance:
/etc/pki-ca/serverCert.profile
It is possible to add AIA, CRLDP, CP OIDs, but the SAN extensions do not appear in the issued CA's SSL server extensions, after the CA configuration, and there are debug log entries like:
[28/Mar/2013:22:20:11][http-7445-Processor25]: SubjectAltNameExtDefault: createExtension i=0
[28/Mar/2013:22:20:11][http-7445-Processor25]: gname is empty, not added
After a CA is configured, the same SAN extension configuration format placed in a regular profile provides issued certificates with the correct expected extensions.
Can SAN extensions be added in the templates used during a pkisilent or web wizard configuration for certificates used by a CA?
Environment
RHEL 5.8
pki-ca-8.1.1-1.el5pki
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
