RE: AD with PKI authentication - issue on cert generation

2020-03-18 Thread Lionel Monchecourt
authentication - issue on cert generation On 18/03/2020 11:35, Lionel Monchecourt wrote: > Hi Matt, > Thanks a lot, > Getting the same error for > msUPN=1.3.6.1.4.1.311.20.2.3, I removed it as well > is it by default in openssl as well ? > btw, removing these 2, I can generate my c

Re: AD with PKI authentication - issue on cert generation

2020-03-18 Thread Matt Caswell
Yes - it exists so removing it should be fine. Matt > > -Original Message- > From: openssl-users [mailto:openssl-users-boun...@openssl.org] On Behalf Of > Matt Caswell > Sent: 17 March 2020 14:10 > To: openssl-users@openssl.org > Subject: Re: AD with PKI au

RE: AD with PKI authentication - issue on cert generation

2020-03-18 Thread Lionel Monchecourt
] On Behalf Of Matt Caswell Sent: 17 March 2020 14:10 To: openssl-users@openssl.org Subject: Re: AD with PKI authentication - issue on cert generation On 17/03/2020 12:33, Lionel Monchecourt wrote: > I already tried to replace > > scardLogin=1.3.6.1.4.1.311.20.2.2 > > with >

Re: AD with PKI authentication - issue on cert generation

2020-03-17 Thread Matt Caswell
On 17/03/2020 12:33, Lionel Monchecourt wrote: > I already tried to replace > > scardLogin=1.3.6.1.4.1.311.20.2.2 > > with > > msSmartcardLogin=1.3.6.1.4.1.311.20.2.2 Try removing this line altogether. OpenSSL already has a built-in object of this name with this OID so it should not be

AD with PKI authentication - issue on cert generation

2020-03-17 Thread Lionel Monchecourt
Hi, I'm trying to install an AD with PKI auth.I'm so referring to : https://wiki.samba.org/index.php/Samba_AD_Smart_Card_Login Let's put aside of course Samba config .. I'm now trying to generate the root CA. Using the template in the wiki , When I try to openssl req -new req -new